Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-57456

Опубликовано: 25 июн. 2026
Источник: redhat
CVSS3: 7.8
EPSS Низкий

Описание

Vim is an open source, command line text editor. Prior to 9.2.0699, Vim's Python omni-completion (runtime/autoload/python3complete.vim and the legacy pythoncomplete.vim) executes reconstructed function and class definitions from the current buffer with exec() as part of populating the completion dictionary. When reconstructing that source, each scope's docstring is inserted verbatim between triple quotes with no escaping, so a hostile buffer can break out of the triple-quoted literal and execute attacker-controlled Python during omni-completion. This vulnerability is fixed in 9.2.0699.

There is a security flaw in Vim. If you use Vim to open a malicious file written by a hacker, and you use the auto-complete feature while typing, the file can secretly force your computer to run unauthorized commands or malware.

Отчет

This flaw is rated as Important. A vulnerability in Vim's Python omni-completion feature allows for arbitrary code execution. By opening a specially crafted file, a local attacker could execute arbitrary Python code due to improper handling of docstrings during omni-completion, leading to a compromise of the system where Vim is running.

Меры по смягчению последствий

To mitigate this vulnerability, users should avoid opening untrusted Python files or using Python omni-completion on such files. If Python omni-completion is not required, it can be disabled by adding autocmd FileType python setlocal omnifunc= to your .vimrc file. This will prevent the vulnerable code from being executed. Disabling Python omni-completion will remove the ability to use Ctrl-X Ctrl-O for Python code completion. A restart of Vim is required for the changes to take effect.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10vimAffected
Red Hat Enterprise Linux 6vimAffected
Red Hat Enterprise Linux 7vimAffected
Red Hat Enterprise Linux 8vimAffected
Red Hat OpenShift Container Platform 4rhcosAffected
Red Hat Enterprise Linux 9vimFixedRHSA-2026:4798229.07.2026
Red Hat Enterprise Linux 9vimFixedRHSA-2026:4798229.07.2026
Red Hat Hardened Imagesvim-main-9.2.780-1.hum1FixedRHSA-2026:3538703.07.2026

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-94
https://bugzilla.redhat.com/show_bug.cgi?id=2492972vim: Vim: Arbitrary code execution via malicious docstrings in Python omni-completion

EPSS

Процентиль: 4%
0.00145
Низкий

7.8 High

CVSS3

Связанные уязвимости

CVSS3: 7.8
ubuntu
около 1 месяца назад

Vim is an open source, command line text editor. Prior to 9.2.0699, Vim's Python omni-completion (runtime/autoload/python3complete.vim and the legacy pythoncomplete.vim) executes reconstructed function and class definitions from the current buffer with exec() as part of populating the completion dictionary. When reconstructing that source, each scope's docstring is inserted verbatim between triple quotes with no escaping, so a hostile buffer can break out of the triple-quoted literal and execute attacker-controlled Python during omni-completion. This vulnerability is fixed in 9.2.0699.

CVSS3: 7.8
nvd
около 1 месяца назад

Vim is an open source, command line text editor. Prior to 9.2.0699, Vim's Python omni-completion (runtime/autoload/python3complete.vim and the legacy pythoncomplete.vim) executes reconstructed function and class definitions from the current buffer with exec() as part of populating the completion dictionary. When reconstructing that source, each scope's docstring is inserted verbatim between triple quotes with no escaping, so a hostile buffer can break out of the triple-quoted literal and execute attacker-controlled Python during omni-completion. This vulnerability is fixed in 9.2.0699.

CVSS3: 7.8
msrc
около 1 месяца назад

Vim: Arbitrary Code Execution via Python Omni-Completion Docstrings

CVSS3: 7.8
debian
около 1 месяца назад

Vim is an open source, command line text editor. Prior to 9.2.0699, Vi ...

rocky
3 дня назад

Important: vim security update

EPSS

Процентиль: 4%
0.00145
Низкий

7.8 High

CVSS3

Уязвимость CVE-2026-57456