Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2026-42307

Опубликовано: 08 мая 2026
Источник: debian

Описание

Vim is an open source, command line text editor. Prior to version 9.2.0383, an OS command injection vulnerability exists in the netrw standard plugin bundled with Vim. By inducing a user to open a crafted URL (e.g., using the sftp:// or file:// protocol handlers), an attacker can execute arbitrary shell commands with the privileges of the Vim process. This issue has been patched in version 9.2.0383.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
vimfixed2:9.2.0428-1package

Примечания

  • https://github.com/vim/vim/security/advisories/GHSA-85ch-p2qr-m5gx

  • Fixed by: https://github.com/vim/vim/commit/405e2fb6d54d5653523809e2853d99d1c000a5fc (v9.2.0383)

Связанные уязвимости

CVSS3: 4.4
ubuntu
3 месяца назад

Vim is an open source, command line text editor. Prior to version 9.2.0383, an OS command injection vulnerability exists in the netrw standard plugin bundled with Vim. By inducing a user to open a crafted URL (e.g., using the sftp:// or file:// protocol handlers), an attacker can execute arbitrary shell commands with the privileges of the Vim process. This issue has been patched in version 9.2.0383.

CVSS3: 4.4
redhat
3 месяца назад

Vim is an open source, command line text editor. Prior to version 9.2.0383, an OS command injection vulnerability exists in the netrw standard plugin bundled with Vim. By inducing a user to open a crafted URL (e.g., using the sftp:// or file:// protocol handlers), an attacker can execute arbitrary shell commands with the privileges of the Vim process. This issue has been patched in version 9.2.0383.

CVSS3: 4.4
nvd
3 месяца назад

Vim is an open source, command line text editor. Prior to version 9.2.0383, an OS command injection vulnerability exists in the netrw standard plugin bundled with Vim. By inducing a user to open a crafted URL (e.g., using the sftp:// or file:// protocol handlers), an attacker can execute arbitrary shell commands with the privileges of the Vim process. This issue has been patched in version 9.2.0383.

CVSS3: 4.4
fstec
3 месяца назад

Уязвимость текстового редактора vim, связанная с непринятием мер по нейтрализации специальных элементов, используемых в команде операционной системы, позволяющая нарушителю выполнить произвольные команды

CVSS3: 4.4
redos
около 1 месяца назад

Уязвимость vim