PT-2026-77154 · Vim+3 · Vim+3
CVE-2026-73073
·
Published
2026-08-18
·
Updated
2026-09-08
CVSS v4.0
7.1
High
| Vector | AV:L/AC:L/AT:P/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Vim versions prior to 9.2.0845
Description
The
StructMembers() function in runtime/autoload/ccomplete.vim constructs and executes a vimgrep command using insufficiently escaped typeref: or typename: values from a tags file. This allows an unterminated collection followed by a command separator to execute arbitrary Ex and operating-system commands when a user invokes C omni-completion using CTRL-X CTRL-O on a member access whose type is resolved from that tags file.Recommendations
Update to version 9.2.0845.
Exploit
Fix
DoS
Code Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Linuxmint
Red Os
Ubuntu
Vim