PT-2026-57015 · Vim+4 · Vim+4

CVE-2026-59858

·

Published

2026-06-27

·

Updated

2026-08-31

CVSS v4.0

8.4

High

VectorAV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Vim versions prior to 9.2.0735
Description The C omni-completion script in runtime/autoload/ccomplete.vim fails to escape the typeref: or typename: extension fields of a tags entry when interpolating them into a :vimgrep pattern executed via :execute. Since :vimgrep treats the bar character as a command separator, a specially crafted tag field can terminate the search pattern and append an arbitrary Ex command. An attacker can achieve remote code execution as the editing user by inducing the user to open a hostile .c file associated with a project tags file containing such a malicious entry and triggering C omni-completion.
Recommendations Update to version 9.2.0735.

Exploit

Fix

Code Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2026:47982
ALSA-2026:48650
ALSA-2026:48703
BDU:2026-14504
CVE-2026-59858
ECHO-60CB-CA68-EA06
GHSA-MF92-V4XW-J45X
OESA-2026-3122
OPENSUSE-SU-2026:21374-1
RHSA-2026:35387
SUSE-SU-2026:22740-1
SUSE-SU-2026:22754-1
SUSE-SU-2026:22797-1
SUSE-SU-2026:22821-1
SUSE-SU-2026:22901-1
SUSE-SU-2026:3237-1
SUSE-SU-2026:3271-1
SUSE-SU-2026:3458-1
USN-8541-1

Affected Products

Linuxmint
Red Os
Rocky Linux
Ubuntu
Vim