Vim is an open source, command line text editor. Prior to 9.2.0357, A command injection vulnerability exists in Vim's tag file processing. When resolving a tag, the filename field from the tags file is passed through wildcard expansion to resolve environment variables and wildcards. If the filename field contains backtick syntax (e.g., `command`), Vim executes the embedded command via the system shell with the full privileges of the running user.
CVSS Details
- CVSS 3.1 Base Score: 6.6
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:H/A:L)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alma_linux | — | Upgrade vim-filesystemUpgrade vim-minimalUpgrade vim-enhancedUpgrade vim-commonUpgrade vim-X11 | Jun 24, 2026 | Jun 23, 2026 |
| Alpine Linux | — | Upgrade vim | Apr 27, 2026 | Apr 24, 2026 |
| Amazon Linux Ami 2 | — | Upgrade vim-enhancedUpgrade vim-filesystemUpgrade vim-minimalUpgrade xxdUpgrade vim-debuginfoUpgrade vim-dataUpgrade vim-commonUpgrade vim-X11 | May 20, 2026 | May 20, 2026 |
| Amazon_linux_2023 | — | Upgrade vim-dataUpgrade vim-enhanced-debuginfoUpgrade vim-minimalUpgrade xxd-debuginfoUpgrade xxdUpgrade vim-minimal-debuginfoUpgrade vim-default-editorUpgrade vim-enhancedUpgrade vim-debuginfoUpgrade vim-debugsourceUpgrade vim-filesystemUpgrade vim-common | May 19, 2026 | Apr 24, 2026 |
| Redhat Openshift | — | Upgrade rhcos | Aug 27, 2026 | Apr 24, 2026 |
| Redhat_linux | — | Upgrade vim-minimalUpgrade vim-enhanced-debuginfoUpgrade vim-debugsourceUpgrade xxdUpgrade vim-common-debuginfoUpgrade vim-X11-debuginfoUpgrade vim-dataUpgrade vim-commonUpgrade vim-enhancedUpgrade vim-minimal-debuginfoUpgrade vim-filesystemUpgrade vim-debuginfoUpgrade vim-X11Upgrade xxd-debuginfo | Jun 24, 2026 | Apr 24, 2026 |
| Rocky_linux | — | Upgrade vim-minimalUpgrade vim-commonUpgrade vim-enhanced-debuginfoUpgrade vim-common-debuginfoUpgrade vim-X11Upgrade vim-X11-debuginfoUpgrade vim-debuginfoUpgrade vim-enhancedUpgrade vim-minimal-debuginfoUpgrade vim-debugsource | Jun 29, 2026 | Jun 25, 2026 |
| Ubuntu | — | Upgrade vim-gtk-py2 (Ubuntu Pro)Upgrade vim-gnome (Ubuntu Pro)Upgrade vim-nox (Ubuntu Pro)Upgrade vim-athenaUpgrade vim-docUpgrade vim-tiny (Ubuntu Pro)Upgrade vim-gnome-py2 (Ubuntu Pro)Upgrade vim-gtk (Ubuntu Pro)Upgrade vim-noxUpgrade vim-commonUpgrade vim-runtimeUpgrade vim-common (Ubuntu Pro)Upgrade vim-gtk3 (Ubuntu Pro)Upgrade vim-gui-commonUpgrade vim-gtk3-py2 (Ubuntu Pro)Upgrade vim-nox-py2 (Ubuntu Pro)Upgrade xxd (Ubuntu Pro)Upgrade xxdUpgrade vimUpgrade vim-lesstif (Ubuntu Pro)Upgrade vim-motifUpgrade vim-athena (Ubuntu Pro)Upgrade vim-gtk3Upgrade vim-gtkUpgrade vim-runtime (Ubuntu Pro)Upgrade vim-tinyUpgrade vim (Ubuntu Pro)Upgrade vim-athena-py2 (Ubuntu Pro) | May 25, 2026 | May 7, 2026 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | Jul 1, 2026 | Apr 24, 2026 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub