https://seclists.org/oss-sec/2026/q3/725: [vim-security] Ex Command Injection in sign_jump() in Vim < v9.2.1090

Published Sep 12, 2026
·
Updated

Affected Software

1 affected component
vim Vim<9.2.1090

Frequently Asked Questions

1

What conditions are required for exploitation?

An attacker needs to cause Vim to handle a buffer whose file name contains an Ex command separator such as `|`, and a user must jump to a sign in that buffer while the buffer is not displayed in any window. In that path, the file name is incorporated into an Ex command without escaping.

2

Which Vim versions are affected?

The issue affects Vim versions earlier than 9.2.1090. The supplied information does not identify affected downstream packages or distributions.

3

How can I assess whether a system is exposed?

Check whether the installed Vim version is earlier than 9.2.1090 and whether users can open or operate on files with attacker-controlled names containing `|`. Exposure specifically depends on use of sign jumping for a buffer that is not currently shown in a window.

4

Is there a CVE identifier for this issue?

A CVE was requested but had not yet been assigned as of the published advisory information.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203