CVE-2026-41411

EUVD-2026-25575
Vim is an open source, command line text editor. Prior to 9.2.0357, A command injection vulnerability exists in Vim's tag file processing. When resolving a tag, the filename field from the tags file is passed through wildcard expansion to resolve environment variables and wildcards. If the filename field contains backtick syntax (e.g., `command`), Vim executes the embedded command via the system shell with the full privileges of the running user.
OS Command Injection
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
6.6 MEDIUM
LOCAL
LOW
NONE
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:H/A:L
Base Score
CVSS 3.x
EPSS Score
Percentile: 34%
Affected Products (NVD)
VendorProductVersion
vimvim
𝑥
< 9.2.0357
𝑥
= Vulnerable software versions
Amazon Linux logo
Amazon Linux Releases
Amazon Package
Release
vim-X11
Amazon Linux 2
2:9.0.2153-1.amzn2.0.6
fixed
vim-common
Amazon Linux 2
2:9.0.2153-1.amzn2.0.6
fixed
Amazon Linux 2023
2:9.2.240-1.amzn2023.0.3
fixed
vim-data
Amazon Linux 2
2:9.0.2153-1.amzn2.0.6
fixed
Amazon Linux 2023
2:9.2.240-1.amzn2023.0.3
fixed
vim-debuginfo
Amazon Linux 2
2:9.0.2153-1.amzn2.0.6
fixed
Amazon Linux 2023
2:9.2.240-1.amzn2023.0.3
fixed
vim-debugsource
Amazon Linux 2023
2:9.2.240-1.amzn2023.0.3
fixed
vim-default-editor
Amazon Linux 2023
2:9.2.240-1.amzn2023.0.3
fixed
vim-enhanced
Amazon Linux 2
2:9.0.2153-1.amzn2.0.6
fixed
Amazon Linux 2023
2:9.2.240-1.amzn2023.0.3
fixed
vim-enhanced-debuginfo
Amazon Linux 2023
2:9.2.240-1.amzn2023.0.3
fixed
vim-filesystem
Amazon Linux 2
2:9.0.2153-1.amzn2.0.6
fixed
Amazon Linux 2023
2:9.2.240-1.amzn2023.0.3
fixed
vim-minimal
Amazon Linux 2
2:9.0.2153-1.amzn2.0.6
fixed
Amazon Linux 2023
2:9.2.240-1.amzn2023.0.3
fixed
vim-minimal-debuginfo
Amazon Linux 2023
2:9.2.240-1.amzn2023.0.3
fixed
xxd
Amazon Linux 2
2:9.0.2153-1.amzn2.0.6
fixed
Amazon Linux 2023
2:9.2.240-1.amzn2023.0.3
fixed
xxd-debuginfo
Amazon Linux 2023
2:9.2.240-1.amzn2023.0.3
fixed
Azure Linux logo
Azure Linux Releases
Azure Package
Release
vim
Azure Linux 3.0
0:9.2.0392-1.azl3
fixed