PT-2026-52474 · Vim+3 · Vim+3

·

CVE-2026-55895

·

Published

2026-06-17

·

Updated

2026-08-31

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Vim versions prior to 9.2.0663
Description A Vimscript code injection issue exists in the s:NetrwLocalRmFile() function within the netrw plugin (runtime/pack/dist/opt/netrw/autoload/netrw.vim) when deleting a local file from the browser. The problem occurs because a filename from the buffer's directory listing is interpolated into an Ex command line passed to :execute with only the backslash character escaped. An attacker can use a crafted filename containing a bar (|) character to terminate the intended command and execute arbitrary Vimscript, which may include shell commands via :call system() and :!.
Recommendations Update to version 9.2.0663.

Exploit

Fix

Code Injection

OS Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

AZL-91104
BDU:2026-14507
CVE-2026-55895
ECHO-090A-B306-0693
GHSA-VHH8-V6WX-HJJH
OESA-2026-2862
OESA-2026-2904
OESA-2026-2905
OESA-2026-2906
USN-8500-1

Affected Products

Linuxmint
Red Os
Ubuntu
Vim