CVE-2026-51400: High severity vim vulnerability
Published Aug 4, 2026
·Updated
An issue in Vim Project v9.2.0389 and earlier allows a local attacker to execute arbitrary code via the vmsfixfilename() function within file vim/src/osvms.c
Affected Software
2 affected components
vim<=9.2.0389
vim Vim<=9.2.0389
Event History
Aug 4, 2026
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·09:16 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2026-51400?
CVE-2026-51400 has a risk rating of 44, indicating a moderate severity vulnerability.
2
How do I fix CVE-2026-51400?
To fix CVE-2026-51400, update to Vim Project version 9.2.0390 or later.
3
What can an attacker do with CVE-2026-51400?
An attacker can execute arbitrary code on the affected system by exploiting CVE-2026-51400.
4
Which versions of Vim are affected by CVE-2026-51400?
Vim Project versions v9.2.0389 and earlier are affected by CVE-2026-51400.
5
What function is responsible for the vulnerability in CVE-2026-51400?
The vms_fixfilename() function within the file vim/src/os_vms.c is responsible for the vulnerability in CVE-2026-51400.