Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

msrc логотип

CVE-2026-41411

Опубликовано: 27 апр. 2026
Источник: msrc
CVSS3: 6.6
EPSS Низкий

Описание

Vim: Command injection via backtick expansion in tag filenames

EPSS

Процентиль: 40%
0.00501
Низкий

6.6 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.6
ubuntu
3 месяца назад

Vim is an open source, command line text editor. Prior to 9.2.0357, A command injection vulnerability exists in Vim's tag file processing. When resolving a tag, the filename field from the tags file is passed through wildcard expansion to resolve environment variables and wildcards. If the filename field contains backtick syntax (e.g., `command`), Vim executes the embedded command via the system shell with the full privileges of the running user.

CVSS3: 7.3
redhat
3 месяца назад

Vim is an open source, command line text editor. Prior to 9.2.0357, A command injection vulnerability exists in Vim's tag file processing. When resolving a tag, the filename field from the tags file is passed through wildcard expansion to resolve environment variables and wildcards. If the filename field contains backtick syntax (e.g., `command`), Vim executes the embedded command via the system shell with the full privileges of the running user.

CVSS3: 6.6
nvd
3 месяца назад

Vim is an open source, command line text editor. Prior to 9.2.0357, A command injection vulnerability exists in Vim's tag file processing. When resolving a tag, the filename field from the tags file is passed through wildcard expansion to resolve environment variables and wildcards. If the filename field contains backtick syntax (e.g., `command`), Vim executes the embedded command via the system shell with the full privileges of the running user.

CVSS3: 6.6
debian
3 месяца назад

Vim is an open source, command line text editor. Prior to 9.2.0357, A ...

CVSS3: 6.6
redos
около 1 месяца назад

Уязвимость vim

EPSS

Процентиль: 40%
0.00501
Низкий

6.6 Medium

CVSS3