PT-2026-57013 · Vim+4 · Vim+4

CVE-2026-59856

·

Published

2026-06-27

·

Updated

2026-08-31

CVSS v4.0

8.4

High

VectorAV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Vim versions prior to 9.2.0736
Description The PHP omni-completion script in runtime/autoload/phpcomplete.vim fails to escape class or trait names taken from the edited buffer before interpolating them into a search() pattern executed via win execute(). An attacker can use a single quote to terminate the search() string argument and use the bar character as an Ex command separator to execute arbitrary Ex commands. By utilizing the :! command, this allows for arbitrary operating-system command execution when a user opens a specially crafted PHP file and triggers omni-completion.
Recommendations Update to version 9.2.0736.

Exploit

Fix

Code Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2026:47982
ALSA-2026:48650
AZL-92160
BDU:2026-14513
CVE-2026-59856
ECHO-EE84-F5BB-81BF
GHSA-FH26-8F79-WJ97
OESA-2026-3122
OPENSUSE-SU-2026:21374-1
RHSA-2026:35387
SUSE-SU-2026:22740-1
SUSE-SU-2026:22754-1
SUSE-SU-2026:22797-1
SUSE-SU-2026:22821-1
SUSE-SU-2026:22901-1
SUSE-SU-2026:3237-1
SUSE-SU-2026:3271-1
SUSE-SU-2026:3458-1
USN-8541-1

Affected Products

Linuxmint
Red Os
Rocky Linux
Ubuntu
Vim