Vim is an open source, command line text editor. Prior to 9.2.0845, StructMembers() in runtime/autoload/ccomplete.vim constructs and executes a vimgrep command using an insufficiently escaped typeref: or typename: value from a tags file, allowing an unterminated collection followed by a command separator to execute arbitrary Ex and operating-system commands when a user invokes C omni-completion with CTRL-X CTRL-O on a member access whose type is resolved from that tags file. This issue is fixed in version 9.2.0845.
CVSS Details
- CVSS 4.0 Base Score: 7.1 (HIGH)
- CVSS 4.0 Vector: (CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade vim | Aug 19, 2026 | Aug 18, 2026 |
| Redhat_linux | — | No solution exists | Sep 11, 2026 | Aug 18, 2026 |
| Ubuntu | — | Upgrade vim-athena (Ubuntu Pro)Upgrade vim-gnome (Ubuntu Pro)Upgrade vim-commonUpgrade vim-gui-commonUpgrade vim-motifUpgrade vim-athenaUpgrade vim-gtk-py2 (Ubuntu Pro)Upgrade vim-tiny (Ubuntu Pro)Upgrade vim-gtk3-py2 (Ubuntu Pro)Upgrade vim-runtime (Ubuntu Pro)Upgrade vim-lesstif (Ubuntu Pro)Upgrade vim-gui-common (Ubuntu Pro)Upgrade xxdUpgrade vim-gtk (Ubuntu Pro)Upgrade vim-nox-py2 (Ubuntu Pro)Upgrade vim-athena-py2 (Ubuntu Pro)Upgrade vim-docUpgrade vim-gtk3 (Ubuntu Pro)Upgrade vim-common (Ubuntu Pro)Upgrade vim-runtimeUpgrade vimUpgrade vim (Ubuntu Pro)Upgrade vim-nox (Ubuntu Pro)Upgrade vim-gnome-py2 (Ubuntu Pro)Upgrade vim-gtkUpgrade vim-tinyUpgrade vim-noxUpgrade vim-gtk3Upgrade xxd (Ubuntu Pro) | Aug 26, 2026 | Aug 25, 2026 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub