PT-2026-57013 · Vim+4 · Vim+4
CVE-2026-59856
·
Published
2026-06-27
·
Updated
2026-08-31
CVSS v4.0
8.4
High
| Vector | AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Vim versions prior to 9.2.0736
Description
The PHP omni-completion script in
runtime/autoload/phpcomplete.vim fails to escape class or trait names taken from the edited buffer before interpolating them into a search() pattern executed via win execute(). An attacker can use a single quote to terminate the search() string argument and use the bar character as an Ex command separator to execute arbitrary Ex commands. By utilizing the :! command, this allows for arbitrary operating-system command execution when a user opens a specially crafted PHP file and triggers omni-completion.Recommendations
Update to version 9.2.0736.
Exploit
Fix
Code Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Linuxmint
Red Os
Rocky Linux
Ubuntu
Vim