PT-2026-48705 · Vim+4 · Vim+4

·

CVE-2026-47162

·

Published

2026-06-11

·

Updated

2026-08-31

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Vim versions prior to 9.2.0495
Description A Vimscript code injection exists in the s:NetrwBookHistSave() function within the netrw plugin. The issue occurs when serializing browsed directory paths to the history file ~/.vim/.netrwhist. A directory name from the filesystem is interpolated into a single-quoted Vimscript string literal without escaping embedded single quotes. This allows a crafted directory name to break the string context and execute arbitrary Vimscript, including shell commands via system() and :!, when the history file is subsequently sourced.
Recommendations Update to version 9.2.0495.

Exploit

Fix

DoS

Special Elements Injection

Code Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2026:38509
ALSA-2026:38510
ALSA-2026:38511
AZL-89778
BDU:2026-10802
CVE-2026-47162
ECHO-1D9F-02A2-CD6E
GHSA-CRM5-RH6J-2C7C
OESA-2026-2761
OESA-2026-2762
OESA-2026-2763
OESA-2026-2863
RHSA-2026:55431
USN-8451-1

Affected Products

Linuxmint
Red Os
Rocky Linux
Ubuntu
Vim