Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 9

Количество 9

ubuntu логотип

CVE-2026-59856

23 дня назад

Vim is an open source, command line text editor. Prior to 9.2.0736, the PHP omni-completion script in runtime/autoload/phpcomplete.vim interpolates a class or trait name, taken from the contents of the edited buffer, into a search() pattern that is run via win_execute() without escaping. A name containing a single quote can terminate the search() string argument early, and because the bar is honored as an Ex command separator, the remainder of the name is run as Ex commands; via the :! command this allows arbitrary operating-system command execution when a victim opens a crafted PHP file and invokes omni-completion. This issue is fixed in version 9.2.0736.

CVSS3: 7.8
EPSS: Низкий
redhat логотип

CVE-2026-59856

23 дня назад

Vim is an open source, command line text editor. Prior to 9.2.0736, the PHP omni-completion script in runtime/autoload/phpcomplete.vim interpolates a class or trait name, taken from the contents of the edited buffer, into a search() pattern that is run via win_execute() without escaping. A name containing a single quote can terminate the search() string argument early, and because the bar is honored as an Ex command separator, the remainder of the name is run as Ex commands; via the :! command this allows arbitrary operating-system command execution when a victim opens a crafted PHP file and invokes omni-completion. This issue is fixed in version 9.2.0736.

CVSS3: 5.3
EPSS: Низкий
nvd логотип

CVE-2026-59856

23 дня назад

Vim is an open source, command line text editor. Prior to 9.2.0736, the PHP omni-completion script in runtime/autoload/phpcomplete.vim interpolates a class or trait name, taken from the contents of the edited buffer, into a search() pattern that is run via win_execute() without escaping. A name containing a single quote can terminate the search() string argument early, and because the bar is honored as an Ex command separator, the remainder of the name is run as Ex commands; via the :! command this allows arbitrary operating-system command execution when a victim opens a crafted PHP file and invokes omni-completion. This issue is fixed in version 9.2.0736.

CVSS3: 7.8
EPSS: Низкий
msrc логотип

CVE-2026-59856

22 дня назад

Vim: Arbitrary Code Execution via PHP Omni-Completion

CVSS3: 7.8
EPSS: Низкий
debian логотип

CVE-2026-59856

23 дня назад

Vim is an open source, command line text editor. Prior to 9.2.0736, th ...

CVSS3: 7.8
EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2026:21374-1

15 дней назад

Security update for vim

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:3271-1

6 дней назад

Security update for vim

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:3237-1

9 дней назад

Security update for vim

EPSS: Низкий
rocky логотип

RLSA-2026:47982

3 дня назад

Important: vim security update

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2026-59856

Vim is an open source, command line text editor. Prior to 9.2.0736, the PHP omni-completion script in runtime/autoload/phpcomplete.vim interpolates a class or trait name, taken from the contents of the edited buffer, into a search() pattern that is run via win_execute() without escaping. A name containing a single quote can terminate the search() string argument early, and because the bar is honored as an Ex command separator, the remainder of the name is run as Ex commands; via the :! command this allows arbitrary operating-system command execution when a victim opens a crafted PHP file and invokes omni-completion. This issue is fixed in version 9.2.0736.

CVSS3: 7.8
0%
Низкий
23 дня назад
redhat логотип
CVE-2026-59856

Vim is an open source, command line text editor. Prior to 9.2.0736, the PHP omni-completion script in runtime/autoload/phpcomplete.vim interpolates a class or trait name, taken from the contents of the edited buffer, into a search() pattern that is run via win_execute() without escaping. A name containing a single quote can terminate the search() string argument early, and because the bar is honored as an Ex command separator, the remainder of the name is run as Ex commands; via the :! command this allows arbitrary operating-system command execution when a victim opens a crafted PHP file and invokes omni-completion. This issue is fixed in version 9.2.0736.

CVSS3: 5.3
0%
Низкий
23 дня назад
nvd логотип
CVE-2026-59856

Vim is an open source, command line text editor. Prior to 9.2.0736, the PHP omni-completion script in runtime/autoload/phpcomplete.vim interpolates a class or trait name, taken from the contents of the edited buffer, into a search() pattern that is run via win_execute() without escaping. A name containing a single quote can terminate the search() string argument early, and because the bar is honored as an Ex command separator, the remainder of the name is run as Ex commands; via the :! command this allows arbitrary operating-system command execution when a victim opens a crafted PHP file and invokes omni-completion. This issue is fixed in version 9.2.0736.

CVSS3: 7.8
0%
Низкий
23 дня назад
msrc логотип
CVE-2026-59856

Vim: Arbitrary Code Execution via PHP Omni-Completion

CVSS3: 7.8
0%
Низкий
22 дня назад
debian логотип
CVE-2026-59856

Vim is an open source, command line text editor. Prior to 9.2.0736, th ...

CVSS3: 7.8
0%
Низкий
23 дня назад
suse-cvrf логотип
openSUSE-SU-2026:21374-1

Security update for vim

15 дней назад
suse-cvrf логотип
SUSE-SU-2026:3271-1

Security update for vim

6 дней назад
suse-cvrf логотип
SUSE-SU-2026:3237-1

Security update for vim

9 дней назад
rocky логотип
RLSA-2026:47982

Important: vim security update

3 дня назад

Уязвимостей на страницу