CVE-2026-43961
EUVD-2026-6241119.08.2026, 14:17
A flaw was found in Vim's netrw plugin. A crafted filename containing quote characters and expression fragments can break out of the quoted context during mark/unmark operations, allowing arbitrary Vimscript execution. This can be leveraged to run shell commands with the privileges of the user running Vim.
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
| Vendor | Product | Version | Source |
|---|---|---|---|
| vim | vim | 𝑥 < 9.2.480 | CNA |
Debian Releases
Ubuntu Releases
Ubuntu Product | |||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| vim |
|
openSUSE / SLES Releases
openSUSE Product | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| gvim |
| ||||||||||||||||||||||||
| vim |
| ||||||||||||||||||||||||
| vim-data |
| ||||||||||||||||||||||||
| vim-data-common |
| ||||||||||||||||||||||||
| vim-small |
|
Amazon Linux Releases
Amazon Package | |||
|---|---|---|---|
| vim-common |
| ||
| vim-data |
| ||
| vim-debuginfo |
| ||
| vim-debugsource |
| ||
| vim-default-editor |
| ||
| vim-enhanced |
| ||
| vim-enhanced-debuginfo |
| ||
| vim-filesystem |
| ||
| vim-minimal |
| ||
| vim-minimal-debuginfo |
| ||
| xxd |
| ||
| xxd-debuginfo |
|