Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-46483

Опубликовано: 15 мая 2026
Источник: redhat
CVSS3: 7

Описание

Vim is an open source, command line text editor. Prior to 9.2.0479, a command injection vulnerability exists in tar#Vimuntar() in runtime/autoload/tar.vim when decompressing .tgz archives on Unix-like systems. The function builds :!gunzip and :!gzip -d commands using shellescape(tartail) without the {special} flag, allowing a crafted archive filename to trigger Vim cmdline-special expansion and execute shell commands in the user's context. This vulnerability is fixed in 9.2.0479.

A flaw was found in Vim. When decompressing .tgz archives, the Vimuntar function builds shell commands using shellescape() without the {special} flag. This allows a specially crafted archive filename to trigger Vim cmdline-special expansion and execute arbitrary commands in the context of the current user.

Отчет

To exploit this issue, an attacker needs to convince a user to decompress a .tgz archive with a specially crafted filename. Additionally, possible arbitrary command execution is restricted to the context of the user running Vim. These conditions limit the exposure of this vulnerability and the potential of a full system compromise. Due to these reasons, this flaw has been rated with a moderate severity.

Меры по смягчению последствий

To mitigate this vulnerability, do not decompress untrusted .tgz archives with the Vimuntar command. Use 'tar -x -z -f' directly, instead.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6vimAffected
Red Hat Enterprise Linux 7vimAffected
Red Hat OpenShift Container Platform 4openshift/ose-rhel-coreos-9Affected
Red Hat Enterprise Linux 10vimFixedRHSA-2026:3850913.07.2026
Red Hat Enterprise Linux 10.0 Extended Update SupportvimFixedRHSA-2026:3090029.06.2026
Red Hat Enterprise Linux 8vimFixedRHSA-2026:3851013.07.2026
Red Hat Enterprise Linux 8vimFixedRHSA-2026:3851013.07.2026
Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update SupportvimFixedRHSA-2026:3345330.06.2026
Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-OnvimFixedRHSA-2026:3345330.06.2026
Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update SupportvimFixedRHSA-2026:3447701.07.2026

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-78
https://bugzilla.redhat.com/show_bug.cgi?id=2477915vim: command injection when decompressing .tgz archives

7 High

CVSS3

Связанные уязвимости

CVSS3: 3.6
ubuntu
4 месяца назад

Vim is an open source, command line text editor. Prior to 9.2.0479, a command injection vulnerability exists in tar#Vimuntar() in runtime/autoload/tar.vim when decompressing .tgz archives on Unix-like systems. The function builds :!gunzip and :!gzip -d commands using shellescape(tartail) without the {special} flag, allowing a crafted archive filename to trigger Vim cmdline-special expansion and execute shell commands in the user's context. This vulnerability is fixed in 9.2.0479.

CVSS3: 3.6
nvd
4 месяца назад

Vim is an open source, command line text editor. Prior to 9.2.0479, a command injection vulnerability exists in tar#Vimuntar() in runtime/autoload/tar.vim when decompressing .tgz archives on Unix-like systems. The function builds :!gunzip and :!gzip -d commands using shellescape(tartail) without the {special} flag, allowing a crafted archive filename to trigger Vim cmdline-special expansion and execute shell commands in the user's context. This vulnerability is fixed in 9.2.0479.

CVSS3: 3.6
msrc
4 месяца назад

Vim: Command injection in tar#Vimuntar via missing shellescape {special} flag

CVSS3: 3.6
debian
4 месяца назад

Vim is an open source, command line text editor. Prior to 9.2.0479, a ...

CVSS3: 7
redos
3 месяца назад

Уязвимость vim

7 High

CVSS3