CVE-2026-59856
EUVD-2026-4275309.07.2026, 23:17
Vim is an open source, command line text editor. Prior to 9.2.0736, the PHP omni-completion script in runtime/autoload/phpcomplete.vim interpolates a class or trait name, taken from the contents of the edited buffer, into a search() pattern that is run via win_execute() without escaping. A name containing a single quote can terminate the search() string argument early, and because the bar is honored as an Ex command separator, the remainder of the name is run as Ex commands; via the :! command this allows arbitrary operating-system command execution when a victim opens a crafted PHP file and invokes omni-completion. This issue is fixed in version 9.2.0736.
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| vim | vim | 𝑥 < 9.2.0736 |
𝑥
= Vulnerable software versions
Debian Releases
Ubuntu Releases
openSUSE / SLES Releases
openSUSE Product | |||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| gvim |
| ||||||||||||||||||||
| vim |
| ||||||||||||||||||||
| vim-data |
| ||||||||||||||||||||
| vim-data-common |
| ||||||||||||||||||||
| vim-small |
|
Red Hat Enterprise Linux Releases
Amazon Linux Releases
Amazon Package | |||||
|---|---|---|---|---|---|
| vim-X11 |
| ||||
| vim-common |
| ||||
| vim-data |
| ||||
| vim-debuginfo |
| ||||
| vim-debugsource |
| ||||
| vim-default-editor |
| ||||
| vim-enhanced |
| ||||
| vim-enhanced-debuginfo |
| ||||
| vim-filesystem |
| ||||
| vim-minimal |
| ||||
| vim-minimal-debuginfo |
| ||||
| xxd |
| ||||
| xxd-debuginfo |
|