CVE-2026-47162

🟡 Monitoruj

Wstrzyknięcie kodu w Vim umożliwia wykonanie dowolnego skryptu Vimscript.

CVSS
8.8
EPSS
0.3%
Exploit
none
Vendor
vim
Opis źródłowy (NVD)

Vim is an open source, command line text editor. Prior to version 9.2.0495, a Vimscript code injection vulnerability exists in s:NetrwBookHistSave() in the netrw plugin (runtime/pack/dist/opt/netrw/autoload/netrw.vim) when serializing browsed directory paths to the history file ~/.vim/.netrwhist. A directory name derived from the filesystem is interpolated into a single-quoted Vimscript string literal without escaping embedded single quotes, allowing a crafted directory name to break out of the string context and execute arbitrary Vimscript, including shell commands via system() and :!, the next time the history file is sourced. This issue has been patched in version 9.2.0495.

brak Brak patcha
Źródła i daty
ŹródłoWartość
NVD – CVSS8.8
CISA KEV (aktywnie wykorzystywane)Nie
FIRST EPSS (prawdopodobieństwo exploita)0.3%
Opublikowano (NVD)2026-06-11 19:16:44 UTC
Ostatnia modyfikacja (NVD)2026-09-18 13:18:28 UTC
Referencje