Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-59858

Опубликовано: 09 июл. 2026
Источник: redhat
CVSS3: 6.5

Описание

Vim is an open source, command line text editor. Prior to 9.2.0735, the C omni-completion script in runtime/autoload/ccomplete.vim interpolates the typeref: or typename: extension field of a tags entry, without escaping, into a :vimgrep pattern that is run through :execute. Because :vimgrep honors the bar as a command separator, a crafted tag field can close the search pattern and append an arbitrary Ex command; opening a hostile .c file whose project tags file contains such an entry and invoking C omni-completion runs that command as the editing user. This issue is fixed in version 9.2.0735.

A command injection vulnerability in Vim's C omni-completion script allows an attacker to execute arbitrary commands if a user is tricked into opening a maliciously crafted tags file and manually invoking the autocomplete feature.

Отчет

This Moderate flaw in Vim's C omni-completion script allows for arbitrary command execution. Exploitation requires a user to open a specially crafted C source file along with a malicious project tags file and then invoke C omni-completion. This limits the attack vector as it relies on specific user interaction and the presence of a hostile tags file, making it less likely to be exploited without user awareness.

Меры по смягчению последствий

Users are advised to avoid opening untrusted C source files or project tags files in Vim. Exercising caution and only processing trusted content prevents exploitation.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6vimAffected
Red Hat Enterprise Linux 7vimAffected
Red Hat OpenShift Container Platform 4openshift/ose-rhel-coreos-8Not affected
Red Hat Enterprise Linux 10vimFixedRHSA-2026:4865031.07.2026
Red Hat Enterprise Linux 10.0 Extended Update SupportvimFixedRHSA-2026:5543117.08.2026
Red Hat Enterprise Linux 8vimFixedRHSA-2026:4870331.07.2026
Red Hat Enterprise Linux 8vimFixedRHSA-2026:4870331.07.2026
Red Hat Enterprise Linux 9vimFixedRHSA-2026:4798229.07.2026
Red Hat Enterprise Linux 9vimFixedRHSA-2026:4798229.07.2026
Red Hat OpenShift Container Platform 4.22rhcos-4.22.9.8.202608130832FixedRHSA-2026:5476918.08.2026

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-94
https://bugzilla.redhat.com/show_bug.cgi?id=2498868vim: Vim: Arbitrary command execution via crafted tags file in C omni-completion

6.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 7.8
ubuntu
2 месяца назад

Vim is an open source, command line text editor. Prior to 9.2.0735, the C omni-completion script in runtime/autoload/ccomplete.vim interpolates the typeref: or typename: extension field of a tags entry, without escaping, into a :vimgrep pattern that is run through :execute. Because :vimgrep honors the bar as a command separator, a crafted tag field can close the search pattern and append an arbitrary Ex command; opening a hostile .c file whose project tags file contains such an entry and invoking C omni-completion runs that command as the editing user. This issue is fixed in version 9.2.0735.

CVSS3: 7.8
nvd
2 месяца назад

Vim is an open source, command line text editor. Prior to 9.2.0735, the C omni-completion script in runtime/autoload/ccomplete.vim interpolates the typeref: or typename: extension field of a tags entry, without escaping, into a :vimgrep pattern that is run through :execute. Because :vimgrep honors the bar as a command separator, a crafted tag field can close the search pattern and append an arbitrary Ex command; opening a hostile .c file whose project tags file contains such an entry and invoking C omni-completion runs that command as the editing user. This issue is fixed in version 9.2.0735.

CVSS3: 7.8
debian
2 месяца назад

Vim is an open source, command line text editor. Prior to 9.2.0735, th ...

CVSS3: 7.8
redos
30 дней назад

Уязвимость vim

CVSS3: 7.8
redos
30 дней назад

Уязвимость vim

6.5 Medium

CVSS3