← Πίσω στην αναζήτηση CVE

CVE-2026-42307

Vim

Περιγραφή

Vim is an open source, command line text editor. Prior to version 9.2.0383, an OS command injection vulnerability exists in the netrw standard plugin bundled with Vim. By inducing a user to open a crafted URL (e.g., using the sftp:// or file:// protocol handlers), an attacker can execute arbitrary shell commands with the privileges of the Vim process. This issue has been patched in version 9.2.0383.

CVSS 4.4EPSS 0.774%Κίνδυνος 0.47
Προβολή πηγής
Δημοσίευση
2026-05-08 23:16:36
Επηρεαζόμενες εκδόσεις
<9.2.0383
Τύπος
Core software
Τελευταία τροποποίηση
2026-07-24 21:10:00
Διάνυσμα
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N