Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2026-52860

Опубликовано: 11 июн. 2026
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS3: 7.8

Описание

Vim is an open source, command line text editor. Prior to version 9.2.0597, Vim's Python omni-completion executes reconstructed function and class definitions from the current buffer with exec() as part of populating the completion dictionary. Python evaluates function default values, parameter annotations, and class base expressions at definition time, so a hostile buffer can execute attacker-controlled Python expressions during omni-completion. The existing g:pythoncomplete_allow_import mitigation (GHSA-52mc-rq6p-rc7c) does not cover this path, because the attacker-controlled code is not a harvested import/from statement. This issue has been patched in version 9.2.0597.

РелизСтатусПримечание
devel

needs-triage

esm-infra-legacy/trusty

released

2:7.4.052-1ubuntu3.1+esm29
esm-infra-legacy/xenial

released

2:7.4.1689-3ubuntu1.5+esm35
esm-infra/bionic

released

2:8.0.1453-1ubuntu1.13+esm20
esm-infra/focal

released

2:8.1.2269-1ubuntu5.32+esm8
jammy

released

2:8.2.3995-1ubuntu2.32
noble

released

2:9.1.0016-1ubuntu7.16
questing

released

2:9.1.0967-1ubuntu6.7
resolute

released

2:9.1.2141-1ubuntu4.5
upstream

not-affected

9.2.597

Показывать по

EPSS

Процентиль: 13%
0.00224
Низкий

7.8 High

CVSS3

Связанные уязвимости

CVSS3: 8
redhat
около 2 месяцев назад

Vim is an open source, command line text editor. Prior to version 9.2.0597, Vim's Python omni-completion executes reconstructed function and class definitions from the current buffer with exec() as part of populating the completion dictionary. Python evaluates function default values, parameter annotations, and class base expressions at definition time, so a hostile buffer can execute attacker-controlled Python expressions during omni-completion. The existing g:pythoncomplete_allow_import mitigation (GHSA-52mc-rq6p-rc7c) does not cover this path, because the attacker-controlled code is not a harvested import/from statement. This issue has been patched in version 9.2.0597.

CVSS3: 7.8
nvd
около 2 месяцев назад

Vim is an open source, command line text editor. Prior to version 9.2.0597, Vim's Python omni-completion executes reconstructed function and class definitions from the current buffer with exec() as part of populating the completion dictionary. Python evaluates function default values, parameter annotations, and class base expressions at definition time, so a hostile buffer can execute attacker-controlled Python expressions during omni-completion. The existing g:pythoncomplete_allow_import mitigation (GHSA-52mc-rq6p-rc7c) does not cover this path, because the attacker-controlled code is not a harvested import/from statement. This issue has been patched in version 9.2.0597.

msrc
около 2 месяцев назад

Vim: Arbitrary Code Execution via Python Omni-Completion

CVSS3: 7.8
debian
около 2 месяцев назад

Vim is an open source, command line text editor. Prior to version 9.2. ...

EPSS

Процентиль: 13%
0.00224
Низкий

7.8 High

CVSS3