https://seclists.org/oss-sec/2026/q3/246: [vim-security] Arbitrary Code Execution via Netrw Menu Construction in Vim < 9.2.0840
Published Jul 23, 2026
·Updated
Affected Software
1 affected component
vim Vim<9.2.0840
Frequently Asked Questions
1
What is the severity of CVE requested for arbitrary code execution in Vim < 9.2.0840?
The severity of CVE requested for arbitrary code execution in Vim < 9.2.0840 is classified as medium.
2
How do I fix CVE requested for arbitrary code execution in Vim < 9.2.0840?
To fix CVE requested for arbitrary code execution in Vim < 9.2.0840, users should upgrade to Vim version 9.2.0840 or later.
3
What vulnerability type is associated with CVE requested for Vim < 9.2.0840?
CVE requested for Vim < 9.2.0840 is associated with improper control of code generation, specifically CWE-94.
4
What is the potential impact of CVE requested for arbitrary code execution in Vim?
The potential impact of CVE requested for arbitrary code execution in Vim includes the execution of arbitrary code, which can compromise system security.
5
When was CVE requested for the vulnerability in Vim published?
CVE requested for the vulnerability in Vim was published on July 23, 2026.