https://seclists.org/oss-sec/2026/q3/259: [vim-security] Arbitrary Command Execution via the Vimball cord File in Vim < 9.2.0847
Published Jul 24, 2026
·Updated
Affected Software
1 affected component
vim Vim<9.2.0847
Frequently Asked Questions
1
What is the severity of CVE requested for Vimball command execution vulnerability?
The severity of the vulnerability is categorized as Medium.
2
How do I fix the command execution vulnerability in Vim below version 9.2.0847?
To fix this vulnerability, upgrade Vim to version 9.2.0847 or later.
3
What type of vulnerability is identified in the Vimball command execution issue?
The vulnerability is classified as Improper Control of Generation of Code (CWE-94).
4
What kind of impact can the command execution vulnerability in Vim cause?
The vulnerability can lead to arbitrary command execution, allowing attackers to execute malicious commands.
5
Is the CVE for the Vimball command execution vulnerability currently assigned?
No, the CVE has been requested but is not yet assigned.