-Infinity
0
Severity
6.6
OS Command Injection, Command Injection
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:H/A:L

Last updated 13 May 2026

1 / 3
Source: Ubuntu
First published (updated )
Severity
7.8
Code Injection, Command Injection
AV:L/AC:H/PR:L/UI:R/S:U/C:L/I:H/A:N

Vim Ex command injection in Vims NetBeans integration

1 / 2
Source: Microsoft
First published (updated )
Severity
7.1
Path Traversal
AV:L/AC:H/PR:N/UI:R/S:C/C:N/I:L/A:L

Last updated 2 July 2026

1 / 3
Source: Ubuntu
First published (updated )
Severity
8.2
OS Command Injection
AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N

Vim is an open source, command line text editor. Prior to version 9.2.0276, a modeline sandbox bypass in Vim allows arbitrary OS command execution when a user opens a crafted file. The complete, guitabtooltip and printheader options are missing the PMLE flag, allowing a modeline to be executed. Additionally, the mapset() function lacks a checksecure() call, allowing it to be abused from sandboxed expressions. Commit 9.2.0276 fixes the issue.

1 / 2
Source: NVD
First published (updated )
Severity
7.8
Buffer Overflow, Use After Free, Input Validation, Integer Overflow, Race Condition
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

AMD. A buffer overflow issue was addressed with improved memory handling.

1 / 65
Source: Apple
First published (updated )
Severity
7.8
Use After Free
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Last updated 24 July 2024

1 / 2
Source: Ubuntu
First published (updated )
Severity
7.8
Use After Free
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Last updated 24 July 2024

1 / 2
Source: Ubuntu
First published (updated )
Severity
7.8
Use After Free
AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Last updated 24 July 2024

1 / 2
Source: Ubuntu
First published (updated )
Severity
7.8
Buffer Overflow, Input Validation, Integer Overflow, Use After Free, Race Condition
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

AMD. A buffer overflow issue was addressed with improved memory handling.

1 / 61
Source: Apple
First published (updated )
Severity
7.8
Buffer Overflow
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Stack-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.0577.

First published (updated )
Severity
5.5
Race Condition, Buffer Overflow, Use After Free, Input Validation, Integer Overflow
AV:L/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:L

Accounts. A privacy issue was addressed with improved private data redaction for log entries.

1 / 47
Source: Apple
First published (updated )
Severity
7.8
Buffer Overflow, Input Validation, Integer Overflow, Use After Free, Race Condition
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

AMD. A buffer overflow issue was addressed with improved memory handling.

1 / 61
Source: Apple
First published (updated )
Severity
7.8
Buffer Overflow
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Heap based buffer overflow in vim/vim 9.0.0946 and below by allowing an attacker to CTRL-W gf in the expression used in the RHS of the substitute command.

First published (updated )
Severity
7.8
Use After Free
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Last updated 24 July 2024

1 / 2
Source: Ubuntu
First published (updated )
Severity
7.8
Use After Free
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Last updated 24 July 2024

1 / 2
Source: Ubuntu
First published (updated )
Severity
7.8
Buffer Overflow
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Last updated 24 July 2024

1 / 2
Source: Ubuntu
First published (updated )
Severity
7.3
Code Injection
CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

Last updated 19 June 2026

1 / 3
Source: Ubuntu
First published (updated )
Severity
7
Code Injection

Vim is an open source, command line text editor. Prior to version 9.2.0495, a Vimscript code injection vulnerability exists in s:NetrwBookHistSave() in the netrw plugin (runtime/pack/dist/opt/netrw/autoload/netrw.vim) when serializing browsed directory paths to the history file ~/.vim/.netrwhist. A directory name derived from the filesystem is interpolated into a single-quoted Vimscript string literal without escaping embedded single quotes, allowing a crafted directory name to break out of the string context and execute arbitrary Vimscript, including shell commands via system() and :!, the next time the history file is sourced. This issue has been patched in version 9.2.0495.

First published (updated )
Severity
7
Race Condition

AIONLYREPORT package: vim-9.1.083-9.el102 ------ Summary: Vimscript injection via unescaped filename in filter() expression in s:NetrwMarkFile(): a crafted filename can break out of the quoted filter() expression during netrw mark/unmark operations and execute arbitrary Vimscript, which can in turn invoke shell commands with the privileges of the Vim user. Requirements to exploit: The attacker must place or induce access to a crafted filename in a directory the victim browses with netrw. The victim must open that directory in Vim and trigger mark/unmark on the malicious entry. Successful exploitation executes attacker-controlled Vimscript and any shell commands it invokes with the privileges of the Vim process. Component affected: Vim netrw implementation - vim91/runtime/autoload/netrw.vim (s:NetrwMarkFile()) Version affected: confirmed in vim-9.1.083-9.el102; available local history shows the vulnerable code from boundary commit e00d3d2 (base vim-9.1.083-9.el10) through current HEAD Patch available: no Version fixed (if any already): unknown Upstream coordination: Not yet notified. This report is the initial triage, and a draft disclosure email is prepared for maintainers. CVSS: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H - 7.8 (HIGH) AV:L - The attacker must control or induce access to a crafted filename in a directory the victim opens locally through Vim/netrw. AC:L - Exploitation requires only crafted filename content; no race condition or special environment is needed beyond using netrw mark/unmark. PR:N - The attacker needs no privileges on the vulnerable Vim instance. UI:R - The victim must browse the directory in netrw and trigger mark/unmark on the crafted entry. S:U - The vulnerable component and the impact remain within the Vim user context. C:H - Arbitrary Vimscript can read files and data accessible to the user running Vim. I:H - Arbitrary Vimscript can modify files or invoke shell commands as that user. A:H - Arbitrary Vimscript or shell commands can disrupt the editor session or destroy user-accessible data. Impact: Important. Successful exploitation leads to arbitrary Vimscript and shell command execution with the privileges of the user running Vim. Although exploitation requires local file placement and explicit user interaction inside netrw, it directly compromises the confidentiality, integrity, and availability of the user's data and environment. Embargo: yes Reason: This issue permits code execution from a crafted filename and no official fix is known yet. Public disclosure before coordination or a fix is available would make social-engineering attacks against users browsing untrusted directories with netrw substantially easier. Suggested public date: 19-Jul-2026 Acknowledgement: Aisle Research

Vulnerability details

In vim91/runtime/autoload/netrw.vim, a:fname from the directory listing is composed into dname and then interpolated directly into a string expression passed to filter(): vim let dname= s:ComposePath(b:netrwcurdir,a:fname) ... call filter(s:netrwmarkfilelist,'v:val != "'.dname.'"') filter({list}, {expr}) evaluates {expr} when it is supplied as a string. A crafted filename containing " and expression fragments can therefore break out of the quoted string during mark/unmark and execute arbitrary Vimscript. Relevant flow: vim nnoremap ... mf :...call <SID>NetrwMarkFile(...,<SID>NetrwGetWord())<cr> fun! s:NetrwGetWord() let dirname= getline('.') return dirname endfun Most relevant CWE identifiers: CWE-94 (Improper Control of Generation of Code)

CWE-74 (Injection into downstream interpreter)

Affected versions

Using available repository history in this checkout: git blame -L 7000,7040 vim91/runtime/autoload/netrw.vim attributes the vulnerable lines to boundary commit e00d3d2 (base vim-9.1.083-9.el10).

Current HEAD in this checkout still contains the vulnerable code.

Based on the available history, the affected range appears to extend from e00d3d2 through current HEAD; earlier upstream introduction could not be confirmed from the truncated history.

Steps to reproduce

1. Create a test directory and a file whose name injects Vimscript into the quoted filter() expression: bash mkdir netrw-poc && cd netrw-poc python3 - <<'PY' from pathlib import Path name = 'x" . execute("silent! !touch netrwinjectionpoc") . "' Path(name).writetext("poc\n") print(name) PY 2. Open Vim in that directory and browse it with netrw (for example, :Ex). 3. Move the cursor to the crafted filename. 4. Press mf once to mark the file, then mf again to unmark it. 5. Observe the command-execution side effect: bash ls -l netrwinjectionpoc

Proposed fix

Use a lambda/Funcref so filter() does not parse attacker-controlled filename data as a Vimscript expression: diff — a/vim91/runtime/autoload/netrw.vim +++ b/vim91/runtime/autoload/netrw.vim @@ call filter(s:netrwmarkfilelist,'v:val != "'.dname.'"') + call filter(s:netrwmarkfilelist, {, v -> v !=# dname})

Alternative safe string form: vim call filter(s:netrwmarkfilelist, 'v:val !=# ' . string(dname)) ------ This report was generated using AI technology. Always review AI-generated content prior to use

First published (updated )
Severity
7

Vim is an open source, command line text editor. Prior to version 9.2.0276, a modeline sandbox bypass in Vim allows arbitrary OS command execution when a user opens a crafted file. The complete, guitabtooltip and printheader options are missing the PMLE flag, allowing a modeline to be executed. Additionally, the mapset() function lacks a checksecure() call, allowing it to be abused from sandboxed expressions. Commit 9.2.0276 fixes the issue.

First published (updated )
Severity
7.1
Code Injection
CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

Last updated 9 September 2026

1 / 3
Source: Ubuntu
First published (updated )
Severity
7.8
Use After Free, Buffer Overflow
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.1848.

1 / 3
First published (updated )
Severity
7.8
Integer Overflow, Use After Free
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Integer Overflow or Wraparound in GitHub repository vim/vim prior to 9.0.1846.

1 / 3
First published (updated )
Severity
7.8
Use After Free
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Last updated 24 July 2024

1 / 3
Source: Ubuntu
First published (updated )
Severity
6.6
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:H

Incorrect Calculation of Buffer Size in GitHub repository vim/vim prior to 9.0.1378.

First published (updated )
Severity
6.6
Buffer Overflow
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:H

Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.1376.

First published (updated )
Severity
6.8
Buffer Overflow
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

Vim is an open source, command line text editor. Prior to 9.2.0842, the socket server backend in src/socketserver.c accepts unbounded client connections in socketserveraccept(), causing descriptors to overflow fdset structures in src/channel.c and fixed-size struct pollfd arrays in src/osunix.c, which allows a local process that can connect to the server socket to corrupt stack memory or terminate the Vim server. This issue is fixed in version 9.2.0842.

1 / 2
Source: NVD
First published (updated )
Severity
8.5
Buffer Overflow
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

Vim is an open source, command line text editor. Prior to 9.2.0846, setsofo() in src/spellfile.c reuses slsalfirst[] without resetting values left by setsalfirst(), so a crafted spell file containing an SNSAL section before an SNSOFO section causes under-counted mapping lists and attacker-influenced writes beyond a heap allocation. This issue is fixed in version 9.2.0846.

1 / 2
Source: MITRE
First published (updated )
Severity
4.2
Use After Free, Double Free
AV:L/AC:H/PR:L/UI:R/S:U/C:L/I:L/A:L

Vim < v9.1.0648 has a double-free in dialogchanged()

1 / 2
Source: Microsoft
First published (updated )
Severity
4.7
Use After Free
CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:L

Last updated 24 July 2024

1 / 2
Source: Ubuntu
First published (updated )

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203