PT-2026-57015 · Vim+4 · Vim+4
CVE-2026-59858
·
Published
2026-06-27
·
Updated
2026-08-31
CVSS v4.0
8.4
High
| Vector | AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Vim versions prior to 9.2.0735
Description
The C omni-completion script in
runtime/autoload/ccomplete.vim fails to escape the typeref: or typename: extension fields of a tags entry when interpolating them into a :vimgrep pattern executed via :execute. Since :vimgrep treats the bar character as a command separator, a specially crafted tag field can terminate the search pattern and append an arbitrary Ex command. An attacker can achieve remote code execution as the editing user by inducing the user to open a hostile .c file associated with a project tags file containing such a malicious entry and triggering C omni-completion.Recommendations
Update to version 9.2.0735.
Exploit
Fix
Code Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Linuxmint
Red Os
Rocky Linux
Ubuntu
Vim