Opened 7 months ago
Closed 7 months ago
#22874 closed enhancement (fixed)
vim-9.2.0078 (Security update)
| Reported by: | Bruce Dubbs | Owned by: | zeckma |
|---|---|---|---|
| Priority: | elevated | Milestone: | 13.0 |
| Component: | BOOK | Version: | git |
| Severity: | medium | Keywords: | |
| Cc: |
Description
An OS command injection vulnerability exists in the netrw standard plugin bundled with Vim. By inducing a user to open a crafted URL (e.g., using thescp:// protocol handler), an attacker can execute arbitrary shell commands with the privileges of the Vim process.
Change History (6)
comment:1 by , 7 months ago
| Milestone: | 13.1 → 13.0 |
|---|
comment:2 by , 7 months ago
| Owner: | changed from to |
|---|---|
| Status: | new → assigned |
comment:4 by , 7 months ago
| Priority: | normal → elevated |
|---|
comment:5 by , 7 months ago
Security fixes
Rating: Medium
- CVE-2026-28417 (Medium): OS Command Injection in
netrw - CVE-2026-28418 (Medium): Heap-based Buffer Overflow in Emacs tags parsing
- CVE-2026-28419 (Medium): Heap-based Buffer Underflow in Emacs tags parsing
- CVE-2026-28420 (Medium): Heap-based Buffer Overflow and OOB Read in
:terminal - CVE-2026-28421 (Medium): Heap-based Buffer Overflow / Improper Input Validation
- CVE-2026-28422 (Low): Stack-buffer-overflow in
build_stl_str_hl()
Note:
See TracTickets
for help on using tickets.

Fixed at commit 11c38e4de2b.
Leaving open for SA.