CVE-2026-43961
7.8
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Summary
A flaw was found in Vim's netrw plugin. A crafted filename containing quote characters and expression fragments can break out of the quoted context during mark/unmark operations, allowing arbitrary Vimscript execution. This can be leveraged to run shell commands with the privileges of the user running Vim.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| vim | vim | 0 < 9.2.0480 | affected |
Weaknesses
- CWE-94: Improper Control of Generation of Code ('Code Injection')
Workarounds
To mitigate this issue, users should avoid browsing untrusted directories or interacting with files from untrusted sources using Vim's netrw plugin. Exercise caution when opening directories that may contain maliciously crafted filenames.
ADP Enrichment
CVE Program Container
Additional References
CISA ADP Vulnrichment
- SSVC:
- Exploitation: none
- Automatable: no
- Technical Impact: total
References
- https://access.redhat.com/security/cve/CVE-2026-43961
- https://bugzilla.redhat.com/show_bug.cgi?id=2460434
- https://github.com/vim/vim/security/advisories/GHSA-66hr-7p6x-x5j3
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.