PT-2026-48721 · Vim+4 · Vim+4

·

CVE-2026-52858

·

Published

2026-05-29

·

Updated

2026-08-31

CVSS v2.0

8.5

High

VectorAV:N/AC:M/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Vim versions prior to 9.2.0561
Description The Python omni-completion script in python3complete.vim (for builds with the +python3 interpreter enabled) and pythoncomplete.vim (for builds with the +python interpreter) executes import and from statements found in the current buffer using Python's import machinery. Since the buffer's working directory is included in sys.path, opening a malicious .py file that has a sibling Python package and triggering omni-completion allows the top-level code of that package to be executed with the privileges of the user editing the file.
Recommendations Update to version 9.2.0561.

Exploit

Fix

DoS

Code Injection

Eval Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2026:38509
ALSA-2026:38510
ALSA-2026:38511
AZL-89781
BDU:2026-14512
CVE-2026-52858
ECHO-C2A9-CB6F-D4B0
GHSA-52MC-RQ6P-RC7C
OESA-2026-2761
OESA-2026-2762
OESA-2026-2763
OESA-2026-2863
USN-8451-1

Affected Products

Linuxmint
Red Os
Rocky Linux
Ubuntu
Vim