Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2026-57456

Опубликовано: 25 июн. 2026
Источник: ubuntu
Приоритет: medium
CVSS3: 7.8

Описание

Vim is an open source, command line text editor. Prior to 9.2.0699, Vim's Python omni-completion (runtime/autoload/python3complete.vim and the legacy pythoncomplete.vim) executes reconstructed function and class definitions from the current buffer with exec() as part of populating the completion dictionary. When reconstructing that source, each scope's docstring is inserted verbatim between triple quotes with no escaping, so a hostile buffer can break out of the triple-quoted literal and execute attacker-controlled Python during omni-completion. This vulnerability is fixed in 9.2.0699.

РелизСтатусПримечание
devel

needs-triage

esm-infra-legacy/trusty

released

2:7.4.052-1ubuntu3.1+esm30
esm-infra-legacy/xenial

released

2:7.4.1689-3ubuntu1.5+esm36
esm-infra/bionic

released

2:8.0.1453-1ubuntu1.13+esm21
esm-infra/focal

released

2:8.1.2269-1ubuntu5.32+esm9
jammy

released

2:8.2.3995-1ubuntu2.33
noble

released

2:9.1.0016-1ubuntu7.17
questing

released

2:9.1.0967-1ubuntu6.8
resolute

released

2:9.1.2141-1ubuntu4.6
upstream

not-affected

9.2.0699

Показывать по

7.8 High

CVSS3

Связанные уязвимости

CVSS3: 7.8
redhat
около 1 месяца назад

Vim is an open source, command line text editor. Prior to 9.2.0699, Vim's Python omni-completion (runtime/autoload/python3complete.vim and the legacy pythoncomplete.vim) executes reconstructed function and class definitions from the current buffer with exec() as part of populating the completion dictionary. When reconstructing that source, each scope's docstring is inserted verbatim between triple quotes with no escaping, so a hostile buffer can break out of the triple-quoted literal and execute attacker-controlled Python during omni-completion. This vulnerability is fixed in 9.2.0699.

CVSS3: 7.8
nvd
около 1 месяца назад

Vim is an open source, command line text editor. Prior to 9.2.0699, Vim's Python omni-completion (runtime/autoload/python3complete.vim and the legacy pythoncomplete.vim) executes reconstructed function and class definitions from the current buffer with exec() as part of populating the completion dictionary. When reconstructing that source, each scope's docstring is inserted verbatim between triple quotes with no escaping, so a hostile buffer can break out of the triple-quoted literal and execute attacker-controlled Python during omni-completion. This vulnerability is fixed in 9.2.0699.

CVSS3: 7.8
msrc
около 1 месяца назад

Vim: Arbitrary Code Execution via Python Omni-Completion Docstrings

CVSS3: 7.8
debian
около 1 месяца назад

Vim is an open source, command line text editor. Prior to 9.2.0699, Vi ...

rocky
3 дня назад

Important: vim security update

7.8 High

CVSS3

Уязвимость CVE-2026-57456