Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-46483

Опубликовано: 15 мая 2026
Источник: redhat
CVSS3: 7

Описание

Vim is an open source, command line text editor. Prior to 9.2.0479, a command injection vulnerability exists in tar#Vimuntar() in runtime/autoload/tar.vim when decompressing .tgz archives on Unix-like systems. The function builds :!gunzip and :!gzip -d commands using shellescape(tartail) without the {special} flag, allowing a crafted archive filename to trigger Vim cmdline-special expansion and execute shell commands in the user's context. This vulnerability is fixed in 9.2.0479.

A flaw was found in Vim. When decompressing .tgz archives, the Vimuntar function builds shell commands using shellescape() without the {special} flag. This allows a specially crafted archive filename to trigger Vim cmdline-special expansion and execute arbitrary commands in the context of the current user.

Отчет

To exploit this issue, an attacker needs to convince a user to decompress a .tgz archive with a specially crafted filename. Additionally, possible arbitrary command execution is restricted to the context of the user running Vim. These conditions limit the exposure of this vulnerability and the potential of a full system compromise. Due to these reasons, this flaw has been rated with a moderate severity.

Меры по смягчению последствий

To mitigate this vulnerability, do not decompress untrusted .tgz archives with the Vimuntar command. Use 'tar -x -z -f' directly, instead.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10vimAffected
Red Hat Enterprise Linux 6vimAffected
Red Hat Enterprise Linux 7vimAffected
Red Hat Enterprise Linux 8vimAffected
Red Hat Enterprise Linux 9vimAffected
Red Hat OpenShift Container Platform 4rhcosAffected
Red Hat Enterprise Linux 10.0 Extended Update SupportvimFixedRHSA-2026:3090029.06.2026
Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update SupportvimFixedRHSA-2026:3345330.06.2026
Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-OnvimFixedRHSA-2026:3345330.06.2026
Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update SupportvimFixedRHSA-2026:3447701.07.2026

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-78
https://bugzilla.redhat.com/show_bug.cgi?id=2477915vim: command injection when decompressing .tgz archives

7 High

CVSS3

Связанные уязвимости

CVSS3: 3.6
ubuntu
3 месяца назад

Vim is an open source, command line text editor. Prior to 9.2.0479, a command injection vulnerability exists in tar#Vimuntar() in runtime/autoload/tar.vim when decompressing .tgz archives on Unix-like systems. The function builds :!gunzip and :!gzip -d commands using shellescape(tartail) without the {special} flag, allowing a crafted archive filename to trigger Vim cmdline-special expansion and execute shell commands in the user's context. This vulnerability is fixed in 9.2.0479.

CVSS3: 3.6
nvd
3 месяца назад

Vim is an open source, command line text editor. Prior to 9.2.0479, a command injection vulnerability exists in tar#Vimuntar() in runtime/autoload/tar.vim when decompressing .tgz archives on Unix-like systems. The function builds :!gunzip and :!gzip -d commands using shellescape(tartail) without the {special} flag, allowing a crafted archive filename to trigger Vim cmdline-special expansion and execute shell commands in the user's context. This vulnerability is fixed in 9.2.0479.

CVSS3: 3.6
msrc
3 месяца назад

Vim: Command injection in tar#Vimuntar via missing shellescape {special} flag

CVSS3: 3.6
debian
3 месяца назад

Vim is an open source, command line text editor. Prior to 9.2.0479, a ...

CVSS3: 7
fstec
3 месяца назад

Уязвимость текстового редактора vim, связанная с непринятием мер по нейтрализации специальных элементов, используемых в команде операционной системы, позволяющая нарушителю выполнить произвольные команды

7 High

CVSS3