PT-2026-45007 · Vim+3 · Vim+3
CVE-2026-43961
·
Published
2026-05-14
·
Updated
2026-09-01
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Vim versions prior to 9.2.480
Description
A flaw in the netrw plugin allows arbitrary Vimscript execution when processing a crafted filename containing quote characters and expression fragments. This occurs during mark/unmark operations, where the input can break out of the quoted context. An attacker can leverage this to execute shell commands with the privileges of the user running Vim. This issue is a result of the software constructing a code segment using externally-influenced input without properly neutralizing special elements that modify the syntax or behavior of the intended code.
Recommendations
Upgrade to version 9.2.480.
Exploit
Fix
Code Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Linuxmint
Red Os
Ubuntu
Vim