PT-2026-48705 · Vim+4 · Vim+4
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Vim versions prior to 9.2.0495
Description
A Vimscript code injection exists in the
s:NetrwBookHistSave() function within the netrw plugin. The issue occurs when serializing browsed directory paths to the history file ~/.vim/.netrwhist. A directory name from the filesystem is interpolated into a single-quoted Vimscript string literal without escaping embedded single quotes. This allows a crafted directory name to break the string context and execute arbitrary Vimscript, including shell commands via system() and :!, when the history file is subsequently sourced.Recommendations
Update to version 9.2.0495.
Exploit
Fix
DoS
Special Elements Injection
Code Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Linuxmint
Red Os
Rocky Linux
Ubuntu
Vim