CVE-2026-57456

EUVD-2026-39436
Vim is an open source, command line text editor. Prior to 9.2.0699, Vim's Python omni-completion (runtime/autoload/python3complete.vim and the legacy pythoncomplete.vim) executes reconstructed function and class definitions from the current buffer with exec() as part of populating the completion dictionary. When reconstructing that source, each scope's docstring is inserted verbatim between triple quotes with no escaping, so a hostile buffer can break out of the triple-quoted literal and execute attacker-controlled Python during omni-completion. This vulnerability is fixed in 9.2.0699.
Code Injection
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
7.8 HIGH
LOCAL
LOW
NONE
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 4.24%
Affected Products (NVD)
VendorProductVersion
vimvim
𝑥
< 9.2.0699
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
vim
bookworm
vulnerable
bullseye
vulnerable
bullseye (security)
vulnerable
forky
2:9.2.0858-1
fixed
sid
2:9.2.0858-1
fixed
trixie
vulnerable
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
vim
bionic
Fixed 2:8.0.1453-1ubuntu1.13+esm21
released
focal
Fixed 2:8.1.2269-1ubuntu5.32+esm9
released
jammy
Fixed 2:8.2.3995-1ubuntu2.33
released
noble
Fixed 2:9.1.0016-1ubuntu7.17
released
questing
Fixed 2:9.1.0967-1ubuntu6.8
released
resolute
Fixed 2:9.1.2141-1ubuntu4.6
released
trusty
Fixed 2:7.4.052-1ubuntu3.1+esm30
released
xenial
Fixed 2:7.4.1689-3ubuntu1.5+esm36
released
Red Hat logo
Red Hat Enterprise Linux Releases
Red Hat Product
Release
vim-X11
RHEL 8
2:8.0.1763-31.el8_10
fixed
RHEL 9
2:8.2.2637-26.el9_8.13
fixed
vim-common
RHEL 8
2:8.0.1763-31.el8_10
fixed
RHEL 9
2:8.2.2637-26.el9_8.13
fixed
vim-enhanced
RHEL 8
2:8.0.1763-31.el8_10
fixed
RHEL 9
2:8.2.2637-26.el9_8.13
fixed
Amazon Linux logo
Amazon Linux Releases
Amazon Package
Release
vim-X11
Amazon Linux 2
2:9.0.2153-1.amzn2.0.8
fixed
vim-common
Amazon Linux 2
2:9.0.2153-1.amzn2.0.8
fixed
Amazon Linux 2023
2:9.2.725-1.amzn2023.0.1
fixed
vim-data
Amazon Linux 2
2:9.0.2153-1.amzn2.0.8
fixed
Amazon Linux 2023
2:9.2.725-1.amzn2023.0.1
fixed
vim-debuginfo
Amazon Linux 2
2:9.0.2153-1.amzn2.0.8
fixed
Amazon Linux 2023
2:9.2.725-1.amzn2023.0.1
fixed
vim-debugsource
Amazon Linux 2023
2:9.2.725-1.amzn2023.0.1
fixed
vim-default-editor
Amazon Linux 2023
2:9.2.725-1.amzn2023.0.1
fixed
vim-enhanced
Amazon Linux 2
2:9.0.2153-1.amzn2.0.8
fixed
Amazon Linux 2023
2:9.2.725-1.amzn2023.0.1
fixed
vim-enhanced-debuginfo
Amazon Linux 2023
2:9.2.725-1.amzn2023.0.1
fixed
vim-filesystem
Amazon Linux 2
2:9.0.2153-1.amzn2.0.8
fixed
Amazon Linux 2023
2:9.2.725-1.amzn2023.0.1
fixed
vim-minimal
Amazon Linux 2
2:9.0.2153-1.amzn2.0.8
fixed
Amazon Linux 2023
2:9.2.725-1.amzn2023.0.1
fixed
vim-minimal-debuginfo
Amazon Linux 2023
2:9.2.725-1.amzn2023.0.1
fixed
xxd
Amazon Linux 2
2:9.0.2153-1.amzn2.0.8
fixed
Amazon Linux 2023
2:9.2.725-1.amzn2023.0.1
fixed
xxd-debuginfo
Amazon Linux 2023
2:9.2.725-1.amzn2023.0.1
fixed
Azure Linux logo
Azure Linux Releases
Azure Package
Release
vim
Azure Linux 3.0
0:9.2.0735-1.azl3
fixed