Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-43961

Опубликовано: 19 авг. 2026
Источник: redhat
CVSS3: 7.8
EPSS Низкий

Описание

A flaw was found in Vim's netrw plugin. A crafted filename containing quote characters and expression fragments can break out of the quoted context during mark/unmark operations, allowing arbitrary Vimscript execution. This can be leveraged to run shell commands with the privileges of the user running Vim.

Отчет

Important: This Vimscript injection flaw in netrw allows arbitrary code execution with user privileges. Exploitation requires a local attacker to place a specially crafted filename in a directory and a victim to browse that directory with netrw and interact with the malicious entry. This directly impacts the confidentiality, integrity, and availability of the user's data and environment.

Меры по смягчению последствий

To mitigate this issue, users should avoid browsing untrusted directories or interacting with files from untrusted sources using Vim's netrw plugin. Exercise caution when opening directories that may contain maliciously crafted filenames.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10vimUnder investigation
Red Hat Enterprise Linux 6vimUnder investigation
Red Hat Enterprise Linux 7vimUnder investigation
Red Hat Enterprise Linux 8vimUnder investigation
Red Hat Enterprise Linux 9vimUnder investigation
Red Hat OpenShift Container Platform 4openshift/ose-rhel-coreos-8Under investigation
Red Hat OpenShift Container Platform 4openshift/ose-rhel-coreos-9Under investigation

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-94
https://bugzilla.redhat.com/show_bug.cgi?id=2460434vim: Vimscript injection via unescaped filename in netrw s:NetrwMarkFile() filter() expression allows arbitrary code execution

EPSS

Процентиль: 5%
0.00159
Низкий

7.8 High

CVSS3

Связанные уязвимости

CVSS3: 7.8
ubuntu
29 дней назад

A flaw was found in Vim's netrw plugin. A crafted filename containing quote characters and expression fragments can break out of the quoted context during mark/unmark operations, allowing arbitrary Vimscript execution. This can be leveraged to run shell commands with the privileges of the user running Vim.

CVSS3: 7.8
nvd
29 дней назад

A flaw was found in Vim's netrw plugin. A crafted filename containing quote characters and expression fragments can break out of the quoted context during mark/unmark operations, allowing arbitrary Vimscript execution. This can be leveraged to run shell commands with the privileges of the user running Vim.

CVSS3: 7.8
debian
29 дней назад

A flaw was found in Vim's netrw plugin. A crafted filename containing ...

CVSS3: 7.8
redos
25 дней назад

Уязвимость vim

CVSS3: 7.8
redos
25 дней назад

Уязвимость vim

EPSS

Процентиль: 5%
0.00159
Низкий

7.8 High

CVSS3