PT-2026-48723 · Vim+3 · Vim+3

·

CVE-2026-52860

·

Published

2026-06-05

·

Updated

2026-08-31

CVSS v2.0

9.3

High

VectorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Vim versions prior to 9.2.0597
Description Python omni-completion in the text editor executes reconstructed function and class definitions from the current buffer using the exec() function to populate the completion dictionary. Because Python evaluates class base expressions, parameter annotations, and function default values during definition, a malicious buffer can trigger the execution of attacker-controlled Python expressions during the omni-completion process. The g:pythoncomplete allow import mitigation is ineffective in this case as the executed code is not an import statement.
Recommendations Update to version 9.2.0597.

Exploit

Fix

Code Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

AZL-89769
BDU:2026-14510
CVE-2026-52860
ECHO-1AE5-1AA8-8736
GHSA-52MC-RQ6P-RC7C
GHSA-65P9-MWWX-7468
OESA-2026-2761
OESA-2026-2762
OESA-2026-2763
OESA-2026-2863
USN-8451-1

Affected Products

Linuxmint
Red Os
Ubuntu
Vim