Vim is an open source, command line text editor. Prior to version 9.2.0383, an OS command injection vulnerability exists in the netrw standard plugin bundled with Vim. By inducing a user to open a crafted URL (e.g., using the sftp:// or file:// protocol handlers), an attacker can execute arbitrary shell commands with the privileges of the Vim process. This issue has been patched in version 9.2.0383.
CVSS Details
- CVSS 3.1 Base Score: 4.4
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade vim | May 15, 2026 | May 8, 2026 |
| Redhat_linux | — | No solution exists | Jul 17, 2026 | May 8, 2026 |
| Ubuntu | — | Upgrade vim-runtimeUpgrade vim-nox-py2 (Ubuntu Pro)Upgrade vim-gtkUpgrade vim-gtk (Ubuntu Pro)Upgrade vim-tinyUpgrade vim-gtk3-py2 (Ubuntu Pro)Upgrade vim-noxUpgrade vim-gui-common (Ubuntu Pro)Upgrade vim-runtime (Ubuntu Pro)Upgrade vim-tiny (Ubuntu Pro)Upgrade vim-nox (Ubuntu Pro)Upgrade vim-common (Ubuntu Pro)Upgrade vim-gtk3Upgrade vim-gtk3 (Ubuntu Pro)Upgrade vim-commonUpgrade vim-gnome (Ubuntu Pro)Upgrade vim-athenaUpgrade vim (Ubuntu Pro)Upgrade vim-athena-py2 (Ubuntu Pro)Upgrade vimUpgrade vim-motifUpgrade vim-gnome-py2 (Ubuntu Pro)Upgrade vim-lesstif (Ubuntu Pro)Upgrade vim-gtk-py2 (Ubuntu Pro)Upgrade vim-athena (Ubuntu Pro)Upgrade vim-gui-common | May 26, 2026 | May 25, 2026 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | Jul 1, 2026 | May 8, 2026 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub