Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-55895

Опубликовано: 25 июн. 2026
Источник: redhat
CVSS3: 7.8
EPSS Низкий

Описание

Vim is an open source, command line text editor. Prior to 9.2.0663, a Vimscript code injection vulnerability exists in s:NetrwLocalRmFile() in the netrw plugin (runtime/pack/dist/opt/netrw/autoload/netrw.vim) when deleting a local file from the browser. A filename derived from the buffer's directory listing is interpolated into an Ex command line passed to :execute with only the backslash character escaped, allowing a crafted filename containing a bar (|) to terminate the intended command and execute arbitrary Vimscript, including shell commands via :call system() and :!. This vulnerability is fixed in 9.2.0663.

A flaw was found in Vim, specifically within the netrw plugin. A local user could exploit a Vimscript code injection vulnerability by attempting to delete a specially crafted local file from the browser. This crafted filename, containing a bar character, could be interpolated into an Ex command, allowing for the execution of arbitrary Vimscript, including shell commands. This could lead to arbitrary code execution on the affected system.

Отчет

This is an Important vulnerability in Vim's netrw plugin that could lead to arbitrary code execution. A local attacker could exploit this flaw by enticing a user to delete a specially crafted file within the netrw file browser, allowing for the injection and execution of arbitrary Vimscript commands, including shell commands. This risk is mitigated by the requirement for local user interaction and a specific sequence of actions.

Меры по смягчению последствий

To mitigate this vulnerability, users should avoid deleting untrusted or suspicious files directly from Vim's netrw file browser. Exercise caution when interacting with files from unknown or untrusted sources within the editor environment.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10vimNot affected
Red Hat Enterprise Linux 6vimNot affected
Red Hat Enterprise Linux 7vimNot affected
Red Hat Enterprise Linux 8vimNot affected
Red Hat Enterprise Linux 9vimNot affected
Red Hat Hardened ImagesvimNot affected
Red Hat OpenShift Container Platform 4openshift/ose-rhel-coreos-8Not affected
Red Hat OpenShift Container Platform 4openshift/ose-rhel-coreos-9Not affected

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-94
https://bugzilla.redhat.com/show_bug.cgi?id=2492970vim: Vim: Arbitrary code execution via Vimscript code injection in netrw plugin

EPSS

Процентиль: 5%
0.00152
Низкий

7.8 High

CVSS3

Связанные уязвимости

CVSS3: 7.8
ubuntu
3 месяца назад

Vim is an open source, command line text editor. Prior to 9.2.0663, a Vimscript code injection vulnerability exists in s:NetrwLocalRmFile() in the netrw plugin (runtime/pack/dist/opt/netrw/autoload/netrw.vim) when deleting a local file from the browser. A filename derived from the buffer's directory listing is interpolated into an Ex command line passed to :execute with only the backslash character escaped, allowing a crafted filename containing a bar (|) to terminate the intended command and execute arbitrary Vimscript, including shell commands via :call system() and :!. This vulnerability is fixed in 9.2.0663.

CVSS3: 7.8
nvd
3 месяца назад

Vim is an open source, command line text editor. Prior to 9.2.0663, a Vimscript code injection vulnerability exists in s:NetrwLocalRmFile() in the netrw plugin (runtime/pack/dist/opt/netrw/autoload/netrw.vim) when deleting a local file from the browser. A filename derived from the buffer's directory listing is interpolated into an Ex command line passed to :execute with only the backslash character escaped, allowing a crafted filename containing a bar (|) to terminate the intended command and execute arbitrary Vimscript, including shell commands via :call system() and :!. This vulnerability is fixed in 9.2.0663.

CVSS3: 7.8
msrc
3 месяца назад

Vim: Vimscript Code Injection in netrw NetrwLocalRmFile() via crafted filename

CVSS3: 7.8
debian
3 месяца назад

Vim is an open source, command line text editor. Prior to 9.2.0663, a ...

CVSS3: 7.8
redos
30 дней назад

Уязвимость vim

EPSS

Процентиль: 5%
0.00152
Низкий

7.8 High

CVSS3