Количество 14
Количество 14
CVE-2026-57456
Vim is an open source, command line text editor. Prior to 9.2.0699, Vim's Python omni-completion (runtime/autoload/python3complete.vim and the legacy pythoncomplete.vim) executes reconstructed function and class definitions from the current buffer with exec() as part of populating the completion dictionary. When reconstructing that source, each scope's docstring is inserted verbatim between triple quotes with no escaping, so a hostile buffer can break out of the triple-quoted literal and execute attacker-controlled Python during omni-completion. This vulnerability is fixed in 9.2.0699.
CVE-2026-57456
Vim is an open source, command line text editor. Prior to 9.2.0699, Vim's Python omni-completion (runtime/autoload/python3complete.vim and the legacy pythoncomplete.vim) executes reconstructed function and class definitions from the current buffer with exec() as part of populating the completion dictionary. When reconstructing that source, each scope's docstring is inserted verbatim between triple quotes with no escaping, so a hostile buffer can break out of the triple-quoted literal and execute attacker-controlled Python during omni-completion. This vulnerability is fixed in 9.2.0699.
CVE-2026-57456
Vim is an open source, command line text editor. Prior to 9.2.0699, Vim's Python omni-completion (runtime/autoload/python3complete.vim and the legacy pythoncomplete.vim) executes reconstructed function and class definitions from the current buffer with exec() as part of populating the completion dictionary. When reconstructing that source, each scope's docstring is inserted verbatim between triple quotes with no escaping, so a hostile buffer can break out of the triple-quoted literal and execute attacker-controlled Python during omni-completion. This vulnerability is fixed in 9.2.0699.
CVE-2026-57456
Vim: Arbitrary Code Execution via Python Omni-Completion Docstrings
CVE-2026-57456
Vim is an open source, command line text editor. Prior to 9.2.0699, Vi ...
ROS-20260819-80-0033
Уязвимость vim
ROS-20260819-73-0033
Уязвимость vim
BDU:2026-14514
Уязвимость механизма автодополнения PHP-кода Python omni-completion модуля python3complete.vim текстового редактора Vim, позволяющая нарушителю выполнить произвольный код
RLSA-2026:48703
Important: vim security update
ELSA-2026-48703
ELSA-2026-48703: vim security update (IMPORTANT)
RLSA-2026:48650
Important: vim security update
RLSA-2026:47982
Important: vim security update
ELSA-2026-48650
ELSA-2026-48650: vim security update (IMPORTANT)
ELSA-2026-47982
ELSA-2026-47982: vim security update (IMPORTANT)
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2026-57456 Vim is an open source, command line text editor. Prior to 9.2.0699, Vim's Python omni-completion (runtime/autoload/python3complete.vim and the legacy pythoncomplete.vim) executes reconstructed function and class definitions from the current buffer with exec() as part of populating the completion dictionary. When reconstructing that source, each scope's docstring is inserted verbatim between triple quotes with no escaping, so a hostile buffer can break out of the triple-quoted literal and execute attacker-controlled Python during omni-completion. This vulnerability is fixed in 9.2.0699. | CVSS3: 7.8 | 0% Низкий | 3 месяца назад | |
CVE-2026-57456 Vim is an open source, command line text editor. Prior to 9.2.0699, Vim's Python omni-completion (runtime/autoload/python3complete.vim and the legacy pythoncomplete.vim) executes reconstructed function and class definitions from the current buffer with exec() as part of populating the completion dictionary. When reconstructing that source, each scope's docstring is inserted verbatim between triple quotes with no escaping, so a hostile buffer can break out of the triple-quoted literal and execute attacker-controlled Python during omni-completion. This vulnerability is fixed in 9.2.0699. | CVSS3: 7.8 | 0% Низкий | 3 месяца назад | |
CVE-2026-57456 Vim is an open source, command line text editor. Prior to 9.2.0699, Vim's Python omni-completion (runtime/autoload/python3complete.vim and the legacy pythoncomplete.vim) executes reconstructed function and class definitions from the current buffer with exec() as part of populating the completion dictionary. When reconstructing that source, each scope's docstring is inserted verbatim between triple quotes with no escaping, so a hostile buffer can break out of the triple-quoted literal and execute attacker-controlled Python during omni-completion. This vulnerability is fixed in 9.2.0699. | CVSS3: 7.8 | 0% Низкий | 3 месяца назад | |
CVE-2026-57456 Vim: Arbitrary Code Execution via Python Omni-Completion Docstrings | CVSS3: 7.8 | 0% Низкий | 3 месяца назад | |
CVE-2026-57456 Vim is an open source, command line text editor. Prior to 9.2.0699, Vi ... | CVSS3: 7.8 | 0% Низкий | 3 месяца назад | |
ROS-20260819-80-0033 Уязвимость vim | CVSS3: 7.8 | 0% Низкий | 30 дней назад | |
ROS-20260819-73-0033 Уязвимость vim | CVSS3: 7.8 | 0% Низкий | 30 дней назад | |
BDU:2026-14514 Уязвимость механизма автодополнения PHP-кода Python omni-completion модуля python3complete.vim текстового редактора Vim, позволяющая нарушителю выполнить произвольный код | CVSS3: 7.8 | 0% Низкий | 3 месяца назад | |
RLSA-2026:48703 Important: vim security update | около 2 месяцев назад | |||
ELSA-2026-48703 ELSA-2026-48703: vim security update (IMPORTANT) | около 2 месяцев назад | |||
RLSA-2026:48650 Important: vim security update | около 2 месяцев назад | |||
RLSA-2026:47982 Important: vim security update | около 2 месяцев назад | |||
ELSA-2026-48650 ELSA-2026-48650: vim security update (IMPORTANT) | около 2 месяцев назад | |||
ELSA-2026-47982 ELSA-2026-47982: vim security update (IMPORTANT) | около 2 месяцев назад |
Уязвимостей на страницу