Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-42307

Опубликовано: 08 мая 2026
Источник: nvd
CVSS3: 4.4
EPSS Низкий

Описание

Vim is an open source, command line text editor. Prior to version 9.2.0383, an OS command injection vulnerability exists in the netrw standard plugin bundled with Vim. By inducing a user to open a crafted URL (e.g., using the sftp:// or file:// protocol handlers), an attacker can execute arbitrary shell commands with the privileges of the Vim process. This issue has been patched in version 9.2.0383.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:vim:vim:*:*:*:*:*:*:*:*
Версия до 9.2.0383 (исключая)

EPSS

Процентиль: 52%
0.00774
Низкий

4.4 Medium

CVSS3

Дефекты

CWE-78

Связанные уязвимости

CVSS3: 4.4
ubuntu
3 месяца назад

Vim is an open source, command line text editor. Prior to version 9.2.0383, an OS command injection vulnerability exists in the netrw standard plugin bundled with Vim. By inducing a user to open a crafted URL (e.g., using the sftp:// or file:// protocol handlers), an attacker can execute arbitrary shell commands with the privileges of the Vim process. This issue has been patched in version 9.2.0383.

CVSS3: 4.4
redhat
3 месяца назад

Vim is an open source, command line text editor. Prior to version 9.2.0383, an OS command injection vulnerability exists in the netrw standard plugin bundled with Vim. By inducing a user to open a crafted URL (e.g., using the sftp:// or file:// protocol handlers), an attacker can execute arbitrary shell commands with the privileges of the Vim process. This issue has been patched in version 9.2.0383.

CVSS3: 4.4
debian
3 месяца назад

Vim is an open source, command line text editor. Prior to version 9.2. ...

CVSS3: 4.4
fstec
3 месяца назад

Уязвимость текстового редактора vim, связанная с непринятием мер по нейтрализации специальных элементов, используемых в команде операционной системы, позволяющая нарушителю выполнить произвольные команды

CVSS3: 4.4
redos
около 1 месяца назад

Уязвимость vim

EPSS

Процентиль: 52%
0.00774
Низкий

4.4 Medium

CVSS3

Дефекты

CWE-78