PT-2026-52478 · Vim+3 · Vim+3

·

CVE-2026-57453

·

Published

2026-06-20

·

Updated

2026-08-31

CVSS v3.1

7.3

High

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:L
Name of the Vulnerable Software and Affected Versions Vim versions 9.1.1784 through 9.2.0677
Description When the bundled zip plugin autoload/zip.vim uses PowerShell to browse, read, extract, update, or delete entries in a zip archive, it constructs the PowerShell command by quoting archive entry names only for the shell and not for PowerShell itself. A specially crafted entry name can escape the intended string context, allowing PowerShell to execute arbitrary commands with the privileges of the user running the application. This is triggered when opening, viewing, or extracting the archive.
Recommendations Update to version 9.2.0678.

Exploit

Fix

DoS

Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

AZL-91119
BDU:2026-14501
CVE-2026-57453
ECHO-E71E-279B-37A1
GHSA-X5FG-H5W9-9FRF
USN-8500-1

Affected Products

Linuxmint
Red Os
Ubuntu
Vim