Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-59856

Опубликовано: 09 июл. 2026
Источник: redhat
CVSS3: 5.3
EPSS Низкий

Описание

Vim is an open source, command line text editor. Prior to 9.2.0736, the PHP omni-completion script in runtime/autoload/phpcomplete.vim interpolates a class or trait name, taken from the contents of the edited buffer, into a search() pattern that is run via win_execute() without escaping. A name containing a single quote can terminate the search() string argument early, and because the bar is honored as an Ex command separator, the remainder of the name is run as Ex commands; via the :! command this allows arbitrary operating-system command execution when a victim opens a crafted PHP file and invokes omni-completion. This issue is fixed in version 9.2.0736.

A flaw was found in Vim, an open-source command-line text editor. The PHP omni-completion script improperly handles specially crafted input. When a victim opens a malicious PHP file and invokes omni-completion, an unescaped class or trait name can be interpreted as Ex commands. This allows a remote attacker to achieve arbitrary operating-system command execution.

Отчет

Red Hat Product Security has rated this vulnerability as having a Moderate impact. While successful exploitation allows for arbitrary operating-system command execution when a user opens a crafted PHP file and triggers omni-completion, this feature is disabled by default in Red Hat products. The requirement for a non-default configuration, combined with mandatory user interaction, significantly reduces the real-world risk."

Меры по смягчению последствий

Users should exercise caution when opening untrusted PHP files and avoid invoking omni-completion on them. To prevent exploitation, the PHP omni-completion script can be disabled by moving or renaming phpcomplete.vim. For example, execute mv /usr/share/vim/vim*/autoload/phpcomplete.vim /usr/share/vim/vim*/autoload/phpcomplete.vim.bak. This action will disable PHP omni-completion functionality. A restart of Vim is necessary for this change to take effect.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10vimAffected
Red Hat Enterprise Linux 6vimAffected
Red Hat Enterprise Linux 7vimAffected
Red Hat Enterprise Linux 8vimAffected
Red Hat OpenShift Container Platform 4rhcosAffected
Red Hat Enterprise Linux 9vimFixedRHSA-2026:4798229.07.2026
Red Hat Enterprise Linux 9vimFixedRHSA-2026:4798229.07.2026
Red Hat Hardened Imagesvim-main-9.2.780-1.hum1FixedRHSA-2026:3538703.07.2026

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-94
https://bugzilla.redhat.com/show_bug.cgi?id=2498867vim: Vim: Arbitrary code execution via crafted PHP file in omni-completion

EPSS

Процентиль: 7%
0.00169
Низкий

5.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 7.8
ubuntu
23 дня назад

Vim is an open source, command line text editor. Prior to 9.2.0736, the PHP omni-completion script in runtime/autoload/phpcomplete.vim interpolates a class or trait name, taken from the contents of the edited buffer, into a search() pattern that is run via win_execute() without escaping. A name containing a single quote can terminate the search() string argument early, and because the bar is honored as an Ex command separator, the remainder of the name is run as Ex commands; via the :! command this allows arbitrary operating-system command execution when a victim opens a crafted PHP file and invokes omni-completion. This issue is fixed in version 9.2.0736.

CVSS3: 7.8
nvd
23 дня назад

Vim is an open source, command line text editor. Prior to 9.2.0736, the PHP omni-completion script in runtime/autoload/phpcomplete.vim interpolates a class or trait name, taken from the contents of the edited buffer, into a search() pattern that is run via win_execute() without escaping. A name containing a single quote can terminate the search() string argument early, and because the bar is honored as an Ex command separator, the remainder of the name is run as Ex commands; via the :! command this allows arbitrary operating-system command execution when a victim opens a crafted PHP file and invokes omni-completion. This issue is fixed in version 9.2.0736.

CVSS3: 7.8
msrc
22 дня назад

Vim: Arbitrary Code Execution via PHP Omni-Completion

CVSS3: 7.8
debian
23 дня назад

Vim is an open source, command line text editor. Prior to 9.2.0736, th ...

suse-cvrf
15 дней назад

Security update for vim

EPSS

Процентиль: 7%
0.00169
Низкий

5.3 Medium

CVSS3