Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-43961

Опубликовано: 19 авг. 2026
Источник: nvd
CVSS3: 7.8
EPSS Низкий

Описание

A flaw was found in Vim's netrw plugin. A crafted filename containing quote characters and expression fragments can break out of the quoted context during mark/unmark operations, allowing arbitrary Vimscript execution. This can be leveraged to run shell commands with the privileges of the user running Vim.

EPSS

Процентиль: 5%
0.00159
Низкий

7.8 High

CVSS3

Дефекты

CWE-94

Связанные уязвимости

CVSS3: 7.8
ubuntu
29 дней назад

A flaw was found in Vim's netrw plugin. A crafted filename containing quote characters and expression fragments can break out of the quoted context during mark/unmark operations, allowing arbitrary Vimscript execution. This can be leveraged to run shell commands with the privileges of the user running Vim.

CVSS3: 7.8
redhat
29 дней назад

A flaw was found in Vim's netrw plugin. A crafted filename containing quote characters and expression fragments can break out of the quoted context during mark/unmark operations, allowing arbitrary Vimscript execution. This can be leveraged to run shell commands with the privileges of the user running Vim.

CVSS3: 7.8
debian
29 дней назад

A flaw was found in Vim's netrw plugin. A crafted filename containing ...

CVSS3: 7.8
redos
25 дней назад

Уязвимость vim

CVSS3: 7.8
redos
25 дней назад

Уязвимость vim

EPSS

Процентиль: 5%
0.00159
Низкий

7.8 High

CVSS3

Дефекты

CWE-94