Last updated 13 May 2026
Vim Ex command injection in Vims NetBeans integration
Last updated 2 July 2026
Vim is an open source, command line text editor. Prior to version 9.2.0276, a modeline sandbox bypass in Vim allows arbitrary OS command execution when a user opens a crafted file. The complete, guitabtooltip and printheader options are missing the PMLE flag, allowing a modeline to be executed. Additionally, the mapset() function lacks a checksecure() call, allowing it to be abused from sandboxed expressions. Commit 9.2.0276 fixes the issue.
AMD. A buffer overflow issue was addressed with improved memory handling.
Last updated 24 July 2024
Last updated 24 July 2024
Last updated 24 July 2024
AMD. A buffer overflow issue was addressed with improved memory handling.
Stack-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.0577.
Accounts. A privacy issue was addressed with improved private data redaction for log entries.
AMD. A buffer overflow issue was addressed with improved memory handling.
Heap based buffer overflow in vim/vim 9.0.0946 and below by allowing an attacker to CTRL-W gf in the expression used in the RHS of the substitute command.
Last updated 24 July 2024
Last updated 24 July 2024
Last updated 24 July 2024
Last updated 19 June 2026
Vim is an open source, command line text editor. Prior to version 9.2.0495, a Vimscript code injection vulnerability exists in s:NetrwBookHistSave() in the netrw plugin (runtime/pack/dist/opt/netrw/autoload/netrw.vim) when serializing browsed directory paths to the history file ~/.vim/.netrwhist. A directory name derived from the filesystem is interpolated into a single-quoted Vimscript string literal without escaping embedded single quotes, allowing a crafted directory name to break out of the string context and execute arbitrary Vimscript, including shell commands via system() and :!, the next time the history file is sourced. This issue has been patched in version 9.2.0495.
AIONLYREPORT package: vim-9.1.083-9.el102 ------ Summary: Vimscript injection via unescaped filename in filter() expression in s:NetrwMarkFile(): a crafted filename can break out of the quoted filter() expression during netrw mark/unmark operations and execute arbitrary Vimscript, which can in turn invoke shell commands with the privileges of the Vim user. Requirements to exploit: The attacker must place or induce access to a crafted filename in a directory the victim browses with netrw. The victim must open that directory in Vim and trigger mark/unmark on the malicious entry. Successful exploitation executes attacker-controlled Vimscript and any shell commands it invokes with the privileges of the Vim process. Component affected: Vim netrw implementation - vim91/runtime/autoload/netrw.vim (s:NetrwMarkFile()) Version affected: confirmed in vim-9.1.083-9.el102; available local history shows the vulnerable code from boundary commit e00d3d2 (base vim-9.1.083-9.el10) through current HEAD Patch available: no Version fixed (if any already): unknown Upstream coordination: Not yet notified. This report is the initial triage, and a draft disclosure email is prepared for maintainers. CVSS: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H - 7.8 (HIGH) AV:L - The attacker must control or induce access to a crafted filename in a directory the victim opens locally through Vim/netrw. AC:L - Exploitation requires only crafted filename content; no race condition or special environment is needed beyond using netrw mark/unmark. PR:N - The attacker needs no privileges on the vulnerable Vim instance. UI:R - The victim must browse the directory in netrw and trigger mark/unmark on the crafted entry. S:U - The vulnerable component and the impact remain within the Vim user context. C:H - Arbitrary Vimscript can read files and data accessible to the user running Vim. I:H - Arbitrary Vimscript can modify files or invoke shell commands as that user. A:H - Arbitrary Vimscript or shell commands can disrupt the editor session or destroy user-accessible data. Impact: Important. Successful exploitation leads to arbitrary Vimscript and shell command execution with the privileges of the user running Vim. Although exploitation requires local file placement and explicit user interaction inside netrw, it directly compromises the confidentiality, integrity, and availability of the user's data and environment. Embargo: yes Reason: This issue permits code execution from a crafted filename and no official fix is known yet. Public disclosure before coordination or a fix is available would make social-engineering attacks against users browsing untrusted directories with netrw substantially easier. Suggested public date: 19-Jul-2026 Acknowledgement: Aisle Research
Vulnerability details
In vim91/runtime/autoload/netrw.vim, a:fname from the directory listing is composed into dname and then interpolated directly into a string expression passed to filter(): vim let dname= s:ComposePath(b:netrwcurdir,a:fname) ... call filter(s:netrwmarkfilelist,'v:val != "'.dname.'"') filter({list}, {expr}) evaluates {expr} when it is supplied as a string. A crafted filename containing " and expression fragments can therefore break out of the quoted string during mark/unmark and execute arbitrary Vimscript. Relevant flow: vim nnoremap ... mf :...call <SID>NetrwMarkFile(...,<SID>NetrwGetWord())<cr> fun! s:NetrwGetWord() let dirname= getline('.') return dirname endfun Most relevant CWE identifiers: CWE-94 (Improper Control of Generation of Code)
CWE-74 (Injection into downstream interpreter)
Affected versions
Using available repository history in this checkout: git blame -L 7000,7040 vim91/runtime/autoload/netrw.vim attributes the vulnerable lines to boundary commit e00d3d2 (base vim-9.1.083-9.el10).
Current HEAD in this checkout still contains the vulnerable code.
Based on the available history, the affected range appears to extend from e00d3d2 through current HEAD; earlier upstream introduction could not be confirmed from the truncated history.
Steps to reproduce
1. Create a test directory and a file whose name injects Vimscript into the quoted filter() expression: bash mkdir netrw-poc && cd netrw-poc python3 - <<'PY' from pathlib import Path name = 'x" . execute("silent! !touch netrwinjectionpoc") . "' Path(name).writetext("poc\n") print(name) PY 2. Open Vim in that directory and browse it with netrw (for example, :Ex). 3. Move the cursor to the crafted filename. 4. Press mf once to mark the file, then mf again to unmark it. 5. Observe the command-execution side effect: bash ls -l netrwinjectionpoc
Proposed fix
Use a lambda/Funcref so filter() does not parse attacker-controlled filename data as a Vimscript expression: diff — a/vim91/runtime/autoload/netrw.vim +++ b/vim91/runtime/autoload/netrw.vim @@ call filter(s:netrwmarkfilelist,'v:val != "'.dname.'"') + call filter(s:netrwmarkfilelist, {, v -> v !=# dname})
Alternative safe string form: vim call filter(s:netrwmarkfilelist, 'v:val !=# ' . string(dname)) ------ This report was generated using AI technology. Always review AI-generated content prior to use
Vim is an open source, command line text editor. Prior to version 9.2.0276, a modeline sandbox bypass in Vim allows arbitrary OS command execution when a user opens a crafted file. The complete, guitabtooltip and printheader options are missing the PMLE flag, allowing a modeline to be executed. Additionally, the mapset() function lacks a checksecure() call, allowing it to be abused from sandboxed expressions. Commit 9.2.0276 fixes the issue.
Last updated 9 September 2026
Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.1848.
Integer Overflow or Wraparound in GitHub repository vim/vim prior to 9.0.1846.
Last updated 24 July 2024
Incorrect Calculation of Buffer Size in GitHub repository vim/vim prior to 9.0.1378.
Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.1376.
Vim is an open source, command line text editor. Prior to 9.2.0842, the socket server backend in src/socketserver.c accepts unbounded client connections in socketserveraccept(), causing descriptors to overflow fdset structures in src/channel.c and fixed-size struct pollfd arrays in src/osunix.c, which allows a local process that can connect to the server socket to corrupt stack memory or terminate the Vim server. This issue is fixed in version 9.2.0842.
Vim is an open source, command line text editor. Prior to 9.2.0846, setsofo() in src/spellfile.c reuses slsalfirst[] without resetting values left by setsalfirst(), so a crafted spell file containing an SNSAL section before an SNSOFO section causes under-counted mapping lists and attacker-influenced writes beyond a heap allocation. This issue is fixed in version 9.2.0846.
Vim < v9.1.0648 has a double-free in dialogchanged()
Last updated 24 July 2024