Description
Vim is an open source, command line text editor. Prior to version 9.2.0383, an OS command injection vulnerability exists in the netrw standard plugin bundled with Vim. By inducing a user to open a crafted URL (e.g., using the sftp:// or file:// protocol handlers), an attacker can execute arbitrary shell commands with the privileges of the Vim process. This issue has been patched in version 9.2.0383.
CVSS 4.4EPSS 0.774%Risque 0.47
Voir la source- Publication
- 2026-05-08 23:16:36
- Versions concernées
- <9.2.0383
- Type
- Core software
- Dernière modification
- 2026-07-24 21:10:00
- Vecteur
- CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N