PT-2026-70268 · Vim+3 · Vim+3

CVE-2026-73078

·

Published

2026-08-11

·

Updated

2026-09-10

CVSS v4.0

8.6

High

VectorAV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Vim versions prior to 9.2.0840
Description In GUI Vim, the runtime/plugin/netrwPlugin.vim loads netrw, and runtime/pack/dist/opt/netrw/autoload/netrw.vim creates Bookmarks, History, and Targets menu entries. The process interpolates attacker-controlled directory paths into executed :menu commands. Specifically, the functions s:NetrwBookmarkMenu(), s:NetrwTgtMenu(), and netrw#MakeTgt(), along with g:netrw menu escape and EX TRLBAR, fail to neutralize single quotes or the | command separator. This allows a crafted path that is browsed or bookmarked to execute arbitrary Ex and operating-system commands.
Recommendations Update to version 9.2.0840.

Exploit

Fix

DoS

Incomplete List of Disallowed Inputs

Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2026:66336
ALSA-2026:66348
ALSA-2026:66366
AZL-95550
CVE-2026-73078
ECHO-8F7E-F3AA-86B0
GHSA-RCR7-F3WR-22R2
OESA-2026-3555
OPENSUSE-SU-2026:21671-1
SUSE-SU-2026:23190-1
SUSE-SU-2026:23365-1
SUSE-SU-2026:23391-1
SUSE-SU-2026:23393-1
SUSE-SU-2026:3677-1
SUSE-SU-2026:3679-1
SUSE-SU-2026:3680-1
USN-8657-1

Affected Products

Linuxmint
Red Os
Ubuntu
Vim