Vim is an open source, command line text editor. Prior to 9.2.0316, a command injection vulnerability in Vim's netbeans interface allows a malicious netbeans server to execute arbitrary Ex commands when Vim connects to it, via unsanitized strings in the defineAnnoType and specialKeys protocol messages. This vulnerability is fixed in 9.2.0316.
CVSS Details
- CVSS 3.1 Base Score: 7.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade vim | Apr 9, 2026 | Apr 8, 2026 |
| Amazon_linux_2023 | — | Upgrade vim-dataUpgrade vim-minimalUpgrade vim-filesystemUpgrade xxdUpgrade vim-enhanced-debuginfoUpgrade xxd-debuginfoUpgrade vim-default-editorUpgrade vim-enhancedUpgrade vim-debuginfoUpgrade vim-debugsourceUpgrade vim-commonUpgrade vim-minimal-debuginfo | Jun 23, 2026 | Apr 8, 2026 |
| Redhat_linux | — | No solution exists | Jul 17, 2026 | Apr 8, 2026 |
| Ubuntu | — | Upgrade vim-tinyUpgrade vim-gtk (Ubuntu Pro)Upgrade vim-gnome (Ubuntu Pro)Upgrade xxdUpgrade vim-noxUpgrade vim-athenaUpgrade vim-docUpgrade vim-nox-py2 (Ubuntu Pro)Upgrade vim-athena (Ubuntu Pro)Upgrade vim-nox (Ubuntu Pro)Upgrade vim-runtime (Ubuntu Pro)Upgrade vim-commonUpgrade vim-runtimeUpgrade vim-gtk3-py2 (Ubuntu Pro)Upgrade vim-gui-common (Ubuntu Pro)Upgrade vim-tiny (Ubuntu Pro)Upgrade vim-gtkUpgrade vimUpgrade vim-motifUpgrade vim-lesstif (Ubuntu Pro)Upgrade vim-athena-py2 (Ubuntu Pro)Upgrade vim-common (Ubuntu Pro)Upgrade vim-gui-commonUpgrade vim-gnome-py2 (Ubuntu Pro)Upgrade vim-gtk3Upgrade vim-gtk-py2 (Ubuntu Pro)Upgrade vim (Ubuntu Pro)Upgrade vim-gtk3 (Ubuntu Pro) | Apr 28, 2026 | Apr 27, 2026 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | Jul 1, 2026 | Apr 8, 2026 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub