Vim is an open source, command line text editor. Prior to version 9.2.0496, a code injection vulnerability exists in s:stepmatch() in the cucumber filetype plugin (runtime/ftplugin/cucumber.vim) on Vim builds with +ruby support. Step-definition patterns read from .rb files under the repository's features/*/ or stories/*/ directories are embedded into a Ruby Kernel.eval argument without sufficient escaping, allowing a crafted pattern in an attacker-controlled repository to execute arbitrary Ruby (and through it arbitrary shell commands) when the user invokes a step-jump mapping ([d, ]d). This issue has been patched in version 9.2.0496.
CVSS Details
- CVSS 4.0 Base Score: 5.1 (MEDIUM)
- CVSS 4.0 Vector: (CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X)
- CVSS 3.1 Base Score: 5.3
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Amazon Linux Ami 2 | — | Upgrade xxdUpgrade vim-dataUpgrade vim-minimalUpgrade vim-X11Upgrade vim-commonUpgrade vim-debuginfoUpgrade vim-enhancedUpgrade vim-filesystem | Jun 23, 2026 | Jun 23, 2026 |
| Redhat Openshift | — | Upgrade rhcos | Aug 19, 2026 | Jun 11, 2026 |
| Redhat_linux | — | Upgrade vim-enhancedUpgrade vim-common-debuginfoUpgrade vim-minimalUpgrade vim-debugsourceUpgrade vim-X11-debuginfoUpgrade vim-enhanced-debuginfoUpgrade vim-debuginfoUpgrade vim-filesystemUpgrade vim-commonUpgrade xxd-debuginfoUpgrade vim-dataUpgrade xxdUpgrade vim-minimal-debuginfoUpgrade vim-X11 | Aug 10, 2026 | Jun 11, 2026 |
| Rocky_linux | — | Upgrade vim-enhanced-debuginfoUpgrade vim-debuginfoUpgrade vim-enhancedUpgrade vim-minimal-debuginfoUpgrade vim-debugsourceUpgrade vim-X11Upgrade vim-common-debuginfoUpgrade vim-X11-debuginfoUpgrade vim-minimalUpgrade vim-common | Aug 13, 2026 | Aug 11, 2026 |
| Ubuntu | — | Upgrade vim (Ubuntu Pro)Upgrade vim-gtkUpgrade vim-motifUpgrade vim-noxUpgrade vim-gui-common (Ubuntu Pro)Upgrade vim-nox (Ubuntu Pro)Upgrade vimUpgrade vim-gtk3 (Ubuntu Pro)Upgrade vim-common (Ubuntu Pro)Upgrade vim-tinyUpgrade vim-gnome-py2 (Ubuntu Pro)Upgrade xxdUpgrade vim-athena-py2 (Ubuntu Pro)Upgrade vim-nox-py2 (Ubuntu Pro)Upgrade vim-gtk (Ubuntu Pro)Upgrade vim-runtimeUpgrade vim-lesstif (Ubuntu Pro)Upgrade vim-gtk3Upgrade xxd (Ubuntu Pro)Upgrade vim-athena (Ubuntu Pro)Upgrade vim-gui-commonUpgrade vim-tiny (Ubuntu Pro)Upgrade vim-athenaUpgrade vim-runtime (Ubuntu Pro)Upgrade vim-gtk3-py2 (Ubuntu Pro)Upgrade vim-gnome (Ubuntu Pro)Upgrade vim-commonUpgrade vim-gtk-py2 (Ubuntu Pro) | Jun 21, 2026 | Jun 18, 2026 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | Jul 1, 2026 | Jun 11, 2026 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub