PT-2026-45007 · Vim+3 · Vim+3

CVE-2026-43961

·

Published

2026-05-14

·

Updated

2026-09-01

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Vim versions prior to 9.2.480
Description A flaw in the netrw plugin allows arbitrary Vimscript execution when processing a crafted filename containing quote characters and expression fragments. This occurs during mark/unmark operations, where the input can break out of the quoted context. An attacker can leverage this to execute shell commands with the privileges of the user running Vim. This issue is a result of the software constructing a code segment using externally-influenced input without properly neutralizing special elements that modify the syntax or behavior of the intended code.
Recommendations Upgrade to version 9.2.480.

Exploit

Fix

Code Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-14527
CVE-2026-43961
ECHO-1A5A-3AD1-CE32
GHSA-66HR-7P6X-X5J3
OESA-2026-2553
OESA-2026-2554
OESA-2026-2686
OESA-2026-2687
OPENSUSE-SU-2026:11114-1
OPENSUSE-SU-2026:20828-1
SUSE-SU-2026:21833-1
SUSE-SU-2026:21840-1
SUSE-SU-2026:21859-1
SUSE-SU-2026:21880-1
SUSE-SU-2026:21944-1
SUSE-SU-2026:2233-1
SUSE-SU-2026:2236-1
SUSE-SU-2026:2313-1
USN-8415-1

Affected Products

Linuxmint
Red Os
Ubuntu
Vim