CVE-2026-55895
EUVD-2026-3945025.06.2026, 16:16
Vim is an open source, command line text editor. Prior to 9.2.0663, a Vimscript code injection vulnerability exists in s:NetrwLocalRmFile() in the netrw plugin (runtime/pack/dist/opt/netrw/autoload/netrw.vim) when deleting a local file from the browser. A filename derived from the buffer's directory listing is interpolated into an Ex command line passed to :execute with only the backslash character escaped, allowing a crafted filename containing a bar (|) to terminate the intended command and execute arbitrary Vimscript, including shell commands via :call system() and :!. This vulnerability is fixed in 9.2.0663.
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| vim | vim | 𝑥 < 9.2.0663 |
𝑥
= Vulnerable software versions
Debian Releases
Ubuntu Releases
Ubuntu Product | |||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| vim |
|
Amazon Linux Releases
Amazon Package | |||||
|---|---|---|---|---|---|
| vim-X11 |
| ||||
| vim-common |
| ||||
| vim-data |
| ||||
| vim-debuginfo |
| ||||
| vim-debugsource |
| ||||
| vim-default-editor |
| ||||
| vim-enhanced |
| ||||
| vim-enhanced-debuginfo |
| ||||
| vim-filesystem |
| ||||
| vim-minimal |
| ||||
| vim-minimal-debuginfo |
| ||||
| xxd |
| ||||
| xxd-debuginfo |
|