Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-28417

Опубликовано: 27 фев. 2026
Источник: nvd
CVSS3: 4.4
CVSS3: 7.8
EPSS Низкий

Описание

Vim is an open source, command line text editor. Prior to version 9.2.0073, an OS command injection vulnerability exists in the netrw standard plugin bundled with Vim. By inducing a user to open a crafted URL (e.g., using the scp:// protocol handler), an attacker can execute arbitrary shell commands with the privileges of the Vim process. Version 9.2.0073 fixes the issue.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:vim:vim:*:*:*:*:*:*:*:*
Версия до 9.2.0073 (исключая)

EPSS

Процентиль: 2%
0.00013
Низкий

4.4 Medium

CVSS3

7.8 High

CVSS3

Дефекты

CWE-86
CWE-78

Связанные уязвимости

CVSS3: 4.4
ubuntu
27 дней назад

Vim is an open source, command line text editor. Prior to version 9.2.0073, an OS command injection vulnerability exists in the `netrw` standard plugin bundled with Vim. By inducing a user to open a crafted URL (e.g., using the `scp://` protocol handler), an attacker can execute arbitrary shell commands with the privileges of the Vim process. Version 9.2.0073 fixes the issue.

CVSS3: 4.4
redhat
27 дней назад

Vim is an open source, command line text editor. Prior to version 9.2.0073, an OS command injection vulnerability exists in the `netrw` standard plugin bundled with Vim. By inducing a user to open a crafted URL (e.g., using the `scp://` protocol handler), an attacker can execute arbitrary shell commands with the privileges of the Vim process. Version 9.2.0073 fixes the issue.

CVSS3: 4.4
msrc
26 дней назад

Vim has OS Command Injection in netrw

CVSS3: 4.4
debian
27 дней назад

Vim is an open source, command line text editor. Prior to version 9.2. ...

CVSS3: 7.8
fstec
28 дней назад

Уязвимость текстового редактора vim, связанная с непринятием мер по нейтрализации специальных элементов, позволяющая нарушителю выполнить произвольные команды

EPSS

Процентиль: 2%
0.00013
Низкий

4.4 Medium

CVSS3

7.8 High

CVSS3

Дефекты

CWE-86
CWE-78