← Back

CVE-2026-42307

nvd nist
Published: May 8, 2026Modified: Jul 24, 2026

JSON object

Loading...
4.4
Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N
Exploitability: 1.8 / Impact: 2.5
Source: security-advisories@github.com (Secondary)

Description

Vim is an open source, command line text editor. Prior to version 9.2.0383, an OS command injection vulnerability exists in the netrw standard plugin bundled with Vim. By inducing a user to open a crafted URL (e.g., using the sftp:// or file:// protocol handlers), an attacker can execute arbitrary shell commands with the privileges of the Vim process. This issue has been patched in version 9.2.0383.

Affected (1)

Products: Vim: Vim
1 product
Vim
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
Before 9.2.0383

References (3)

Source: security-advisories@github.com
Product
Source: security-advisories@github.com
PatchVendor Advisory

Timeline

No history available yet.