← Back to CVE search

CVE-2026-57456

Vim

Description

Vim is an open source, command line text editor. Prior to 9.2.0699, Vim-s Python omni-completion (runtime/autoload/python3complete.vim and the legacy pythoncomplete.vim) executes reconstructed function and class definitions from the current buffer with exec() as part of populating the completion dictionary. When reconstructing that source, each scope-s docstring is inserted verbatim between triple quotes with no escaping, so a hostile buffer can break out of the triple-quoted literal and execute attacker-controlled Python during omni-completion. This vulnerability is fixed in 9.2.0699.

CVSS 7.8EPSS 0.145%Risk 0.79
View source
Published
2026-06-25 16:16:42
Affected versions
<9.2.0699
Type
Critical software
Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H