PT-2026-70268 · Vim+3 · Vim+3
CVE-2026-73078
·
Published
2026-08-11
·
Updated
2026-09-10
CVSS v4.0
8.6
High
| Vector | AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Vim versions prior to 9.2.0840
Description
In GUI Vim, the
runtime/plugin/netrwPlugin.vim loads netrw, and runtime/pack/dist/opt/netrw/autoload/netrw.vim creates Bookmarks, History, and Targets menu entries. The process interpolates attacker-controlled directory paths into executed :menu commands. Specifically, the functions s:NetrwBookmarkMenu(), s:NetrwTgtMenu(), and netrw#MakeTgt(), along with g:netrw menu escape and EX TRLBAR, fail to neutralize single quotes or the | command separator. This allows a crafted path that is browsed or bookmarked to execute arbitrary Ex and operating-system commands.Recommendations
Update to version 9.2.0840.
Exploit
Fix
DoS
Incomplete List of Disallowed Inputs
Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Linuxmint
Red Os
Ubuntu
Vim