Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 8

Количество 8

ubuntu логотип

CVE-2026-57453

3 месяца назад

Vim is an open source, command line text editor. From 9.1.1784 until 9.2.0678, when the bundled zip plugin autoload/zip.vim falls back to PowerShell to browse, read, extract, update or delete entries in a zip archive, it builds the PowerShell command by inserting archive entry names that are quoted only for the shell, not for PowerShell. A crafted entry name can break out of the intended string context and cause PowerShell to execute arbitrary commands with the privileges of the user running Vim, triggered by opening, viewing or extracting the archive. This vulnerability is fixed in 9.2.0678.

CVSS3: 6.5
EPSS: Низкий
redhat логотип

CVE-2026-57453

3 месяца назад

Vim is an open source, command line text editor. From 9.1.1784 until 9.2.0678, when the bundled zip plugin autoload/zip.vim falls back to PowerShell to browse, read, extract, update or delete entries in a zip archive, it builds the PowerShell command by inserting archive entry names that are quoted only for the shell, not for PowerShell. A crafted entry name can break out of the intended string context and cause PowerShell to execute arbitrary commands with the privileges of the user running Vim, triggered by opening, viewing or extracting the archive. This vulnerability is fixed in 9.2.0678.

CVSS3: 5.8
EPSS: Низкий
nvd логотип

CVE-2026-57453

3 месяца назад

Vim is an open source, command line text editor. From 9.1.1784 until 9.2.0678, when the bundled zip plugin autoload/zip.vim falls back to PowerShell to browse, read, extract, update or delete entries in a zip archive, it builds the PowerShell command by inserting archive entry names that are quoted only for the shell, not for PowerShell. A crafted entry name can break out of the intended string context and cause PowerShell to execute arbitrary commands with the privileges of the user running Vim, triggered by opening, viewing or extracting the archive. This vulnerability is fixed in 9.2.0678.

CVSS3: 6.5
EPSS: Низкий
msrc логотип

CVE-2026-57453

3 месяца назад

Vim: PowerShell Command Injection via Unescaped Filename in zip.vim Extraction

CVSS3: 6.5
EPSS: Низкий
debian логотип

CVE-2026-57453

3 месяца назад

Vim is an open source, command line text editor. From 9.1.1784 until 9 ...

CVSS3: 6.5
EPSS: Низкий
redos логотип

ROS-20260819-80-0024

30 дней назад

Уязвимость vim

CVSS3: 7.3
EPSS: Низкий
redos логотип

ROS-20260819-73-0024

30 дней назад

Уязвимость vim

CVSS3: 7.3
EPSS: Низкий
fstec логотип

BDU:2026-14501

3 месяца назад

Уязвимость встроенного ZIP-плагин модуля runtime/autoload/zip.vim текстового редактора Vim, позволяющая нарушителю выполнить произвольные команды

CVSS3: 7.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2026-57453

Vim is an open source, command line text editor. From 9.1.1784 until 9.2.0678, when the bundled zip plugin autoload/zip.vim falls back to PowerShell to browse, read, extract, update or delete entries in a zip archive, it builds the PowerShell command by inserting archive entry names that are quoted only for the shell, not for PowerShell. A crafted entry name can break out of the intended string context and cause PowerShell to execute arbitrary commands with the privileges of the user running Vim, triggered by opening, viewing or extracting the archive. This vulnerability is fixed in 9.2.0678.

CVSS3: 6.5
0%
Низкий
3 месяца назад
redhat логотип
CVE-2026-57453

Vim is an open source, command line text editor. From 9.1.1784 until 9.2.0678, when the bundled zip plugin autoload/zip.vim falls back to PowerShell to browse, read, extract, update or delete entries in a zip archive, it builds the PowerShell command by inserting archive entry names that are quoted only for the shell, not for PowerShell. A crafted entry name can break out of the intended string context and cause PowerShell to execute arbitrary commands with the privileges of the user running Vim, triggered by opening, viewing or extracting the archive. This vulnerability is fixed in 9.2.0678.

CVSS3: 5.8
0%
Низкий
3 месяца назад
nvd логотип
CVE-2026-57453

Vim is an open source, command line text editor. From 9.1.1784 until 9.2.0678, when the bundled zip plugin autoload/zip.vim falls back to PowerShell to browse, read, extract, update or delete entries in a zip archive, it builds the PowerShell command by inserting archive entry names that are quoted only for the shell, not for PowerShell. A crafted entry name can break out of the intended string context and cause PowerShell to execute arbitrary commands with the privileges of the user running Vim, triggered by opening, viewing or extracting the archive. This vulnerability is fixed in 9.2.0678.

CVSS3: 6.5
0%
Низкий
3 месяца назад
msrc логотип
CVE-2026-57453

Vim: PowerShell Command Injection via Unescaped Filename in zip.vim Extraction

CVSS3: 6.5
0%
Низкий
3 месяца назад
debian логотип
CVE-2026-57453

Vim is an open source, command line text editor. From 9.1.1784 until 9 ...

CVSS3: 6.5
0%
Низкий
3 месяца назад
redos логотип
ROS-20260819-80-0024

Уязвимость vim

CVSS3: 7.3
0%
Низкий
30 дней назад
redos логотип
ROS-20260819-73-0024

Уязвимость vim

CVSS3: 7.3
0%
Низкий
30 дней назад
fstec логотип
BDU:2026-14501

Уязвимость встроенного ZIP-плагин модуля runtime/autoload/zip.vim текстового редактора Vim, позволяющая нарушителю выполнить произвольные команды

CVSS3: 7.3
0%
Низкий
3 месяца назад

Уязвимостей на страницу