Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-28417

Опубликовано: 27 фев. 2026
Источник: nvd
CVSS3: 4.4
CVSS3: 7.8
EPSS Низкий

Описание

Vim is an open source, command line text editor. Prior to version 9.2.0073, an OS command injection vulnerability exists in the netrw standard plugin bundled with Vim. By inducing a user to open a crafted URL (e.g., using the scp:// protocol handler), an attacker can execute arbitrary shell commands with the privileges of the Vim process. Version 9.2.0073 fixes the issue.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:vim:vim:*:*:*:*:*:*:*:*
Версия до 9.2.0073 (исключая)

EPSS

Процентиль: 64%
0.01162
Низкий

4.4 Medium

CVSS3

7.8 High

CVSS3

Дефекты

CWE-86
CWE-78

Связанные уязвимости

CVSS3: 4.4
ubuntu
5 месяцев назад

Vim is an open source, command line text editor. Prior to version 9.2.0073, an OS command injection vulnerability exists in the `netrw` standard plugin bundled with Vim. By inducing a user to open a crafted URL (e.g., using the `scp://` protocol handler), an attacker can execute arbitrary shell commands with the privileges of the Vim process. Version 9.2.0073 fixes the issue.

CVSS3: 4.4
redhat
5 месяцев назад

Vim is an open source, command line text editor. Prior to version 9.2.0073, an OS command injection vulnerability exists in the `netrw` standard plugin bundled with Vim. By inducing a user to open a crafted URL (e.g., using the `scp://` protocol handler), an attacker can execute arbitrary shell commands with the privileges of the Vim process. Version 9.2.0073 fixes the issue.

CVSS3: 4.4
msrc
5 месяцев назад

Vim has OS Command Injection in netrw

CVSS3: 4.4
debian
5 месяцев назад

Vim is an open source, command line text editor. Prior to version 9.2. ...

CVSS3: 7.8
fstec
5 месяцев назад

Уязвимость текстового редактора vim, связанная с непринятием мер по нейтрализации специальных элементов, позволяющая нарушителю выполнить произвольные команды

EPSS

Процентиль: 64%
0.01162
Низкий

4.4 Medium

CVSS3

7.8 High

CVSS3

Дефекты

CWE-86
CWE-78