A flaw was found in Vim's netrw plugin. A crafted filename containing quote characters and expression fragments can break out of the quoted context during mark/unmark operations, allowing arbitrary Vimscript execution. This can be leveraged to run shell commands with the privileges of the user running Vim.
CVSS Details
- CVSS 3.1 Base Score: 7.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade vim | Aug 20, 2026 | Aug 19, 2026 |
| Redhat_linux | — | No solution exists | Sep 23, 2026 | Aug 19, 2026 |
| Ubuntu | — | Upgrade vim-gtk (Ubuntu Pro)Upgrade xxdUpgrade vim-common (Ubuntu Pro)Upgrade xxd (Ubuntu Pro)Upgrade vim-athenaUpgrade vim-runtime (Ubuntu Pro)Upgrade vim-motifUpgrade vim-tinyUpgrade vim (Ubuntu Pro)Upgrade vim-gtkUpgrade vim-gtk-py2 (Ubuntu Pro)Upgrade vimUpgrade vim-nox-py2 (Ubuntu Pro)Upgrade vim-lesstif (Ubuntu Pro)Upgrade vim-athena-py2 (Ubuntu Pro)Upgrade vim-noxUpgrade vim-commonUpgrade vim-gnome (Ubuntu Pro)Upgrade vim-athena (Ubuntu Pro)Upgrade vim-gtk3Upgrade vim-nox (Ubuntu Pro)Upgrade vim-gui-common (Ubuntu Pro)Upgrade vim-gtk3 (Ubuntu Pro)Upgrade vim-runtimeUpgrade vim-gui-commonUpgrade vim-tiny (Ubuntu Pro)Upgrade vim-gtk3-py2 (Ubuntu Pro)Upgrade vim-gnome-py2 (Ubuntu Pro) | Jun 16, 2026 | Jun 9, 2026 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub