Vim is an open source, command line text editor. Prior to 9.2.0699, Vim's Python omni-completion (runtime/autoload/python3complete.vim and the legacy pythoncomplete.vim) executes reconstructed function and class definitions from the current buffer with exec() as part of populating the completion dictionary. When reconstructing that source, each scope's docstring is inserted verbatim between triple quotes with no escaping, so a hostile buffer can break out of the triple-quoted literal and execute attacker-controlled Python during omni-completion. This vulnerability is fixed in 9.2.0699.
CVSS Details
- CVSS 4.0 Base Score: 8.4 (HIGH)
- CVSS 4.0 Vector: (CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X)
- CVSS 3.1 Base Score: 7.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alma_linux | — | Upgrade vim-minimalUpgrade vim-commonUpgrade vim-filesystemUpgrade vim-X11Upgrade vim-enhanced | Aug 2, 2026 | Jul 29, 2026 |
| Alpine Linux | — | Upgrade vim | Jun 26, 2026 | Jun 25, 2026 |
| Amazon Linux Ami 2 | — | Upgrade vim-X11Upgrade xxdUpgrade vim-dataUpgrade vim-commonUpgrade vim-filesystemUpgrade vim-enhancedUpgrade vim-minimalUpgrade vim-debuginfo | Jul 22, 2026 | Jul 22, 2026 |
| Amazon_linux_2023 | — | Upgrade vim-commonUpgrade vim-filesystemUpgrade vim-debugsourceUpgrade xxd-debuginfoUpgrade vim-debuginfoUpgrade vim-default-editorUpgrade xxdUpgrade vim-minimalUpgrade vim-enhanced-debuginfoUpgrade vim-enhancedUpgrade vim-minimal-debuginfoUpgrade vim-data | Jul 21, 2026 | Jun 25, 2026 |
| Redhat Openshift | — | Upgrade rhcos | Aug 19, 2026 | Jun 25, 2026 |
| Redhat_linux | — | Upgrade vim-enhancedUpgrade vim-enhanced-debuginfoUpgrade vim-X11Upgrade xxdUpgrade xxd-debuginfoUpgrade vim-debuginfoUpgrade vim-dataUpgrade vim-common-debuginfoUpgrade vim-minimalUpgrade vim-X11-debuginfoUpgrade vim-debugsourceUpgrade vim-commonUpgrade vim-filesystem | Jul 17, 2026 | Jun 25, 2026 |
| Rocky_linux | — | Upgrade vim-enhancedUpgrade vim-enhanced-debuginfoUpgrade vim-minimal-debuginfoUpgrade vim-debuginfoUpgrade vim-X11Upgrade vim-commonUpgrade vim-debugsourceUpgrade vim-common-debuginfoUpgrade vim-X11-debuginfoUpgrade vim-minimal | Aug 3, 2026 | Jul 31, 2026 |
| Ubuntu | — | Upgrade vim-gtk3-py2 (Ubuntu Pro)Upgrade vim-gtk-py2 (Ubuntu Pro)Upgrade vim-gui-commonUpgrade vim-athena (Ubuntu Pro)Upgrade vim-gnome-py2 (Ubuntu Pro)Upgrade vim-commonUpgrade vim-gtk3 (Ubuntu Pro)Upgrade vim-gtk3Upgrade vim-runtime (Ubuntu Pro)Upgrade vim-noxUpgrade vim-nox (Ubuntu Pro)Upgrade vim-gnome (Ubuntu Pro)Upgrade vim-nox-py2 (Ubuntu Pro)Upgrade xxd (Ubuntu Pro)Upgrade vim-tiny (Ubuntu Pro)Upgrade vim-common (Ubuntu Pro)Upgrade vim-athena-py2 (Ubuntu Pro)Upgrade vim-gtkUpgrade vimUpgrade vim-runtimeUpgrade vim-gtk (Ubuntu Pro)Upgrade vim-motifUpgrade vim-lesstif (Ubuntu Pro)Upgrade xxdUpgrade vim (Ubuntu Pro)Upgrade vim-athenaUpgrade vim-gui-common (Ubuntu Pro)Upgrade vim-tiny | Jul 5, 2026 | Jul 2, 2026 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | Aug 13, 2026 | Jun 25, 2026 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub