PT-2026-77154 · Vim+3 · Vim+3

CVE-2026-73073

·

Published

2026-08-18

·

Updated

2026-09-08

CVSS v4.0

7.1

High

VectorAV:L/AC:L/AT:P/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Vim versions prior to 9.2.0845
Description The StructMembers() function in runtime/autoload/ccomplete.vim constructs and executes a vimgrep command using insufficiently escaped typeref: or typename: values from a tags file. This allows an unterminated collection followed by a command separator to execute arbitrary Ex and operating-system commands when a user invokes C omni-completion using CTRL-X CTRL-O on a member access whose type is resolved from that tags file.
Recommendations Update to version 9.2.0845.

Exploit

Fix

DoS

Code Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

AZL-96767
CVE-2026-73073
ECHO-541C-D60F-BECF
GHSA-CX73-PHCG-3J5G
USN-8679-1
USN-8679-2

Affected Products

Linuxmint
Red Os
Ubuntu
Vim