Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2026-73073

Опубликовано: 18 авг. 2026
Источник: debian

Описание

Vim is an open source, command line text editor. Prior to 9.2.0845, StructMembers() in runtime/autoload/ccomplete.vim constructs and executes a vimgrep command using an insufficiently escaped typeref: or typename: value from a tags file, allowing an unterminated collection followed by a command separator to execute arbitrary Ex and operating-system commands when a user invokes C omni-completion with CTRL-X CTRL-O on a member access whose type is resolved from that tags file. This issue is fixed in version 9.2.0845.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
vimfixed2:9.2.0858-1package

Примечания

  • https://github.com/vim/vim/security/advisories/GHSA-cx73-phcg-3j5g

  • Fixed by: https://github.com/vim/vim/commit/2f628d8104958fa7421664f792ca6d4f7a39a10f (v9.2.0845)

Связанные уязвимости

ubuntu
10 дней назад

(Vim is an open source, command line text editor. Prior to 9.2.0845, St ...)

nvd
10 дней назад

Vim is an open source, command line text editor. Prior to 9.2.0845, StructMembers() in runtime/autoload/ccomplete.vim constructs and executes a vimgrep command using an insufficiently escaped typeref: or typename: value from a tags file, allowing an unterminated collection followed by a command separator to execute arbitrary Ex and operating-system commands when a user invokes C omni-completion with CTRL-X CTRL-O on a member access whose type is resolved from that tags file. This issue is fixed in version 9.2.0845.

msrc
8 дней назад

Vim: Arbitrary Ex Command Execution in C Omni-Completion