← Retour à la recherche de CVE

CVE-2026-57456

Vim

Description

Vim is an open source, command line text editor. Prior to 9.2.0699, Vim-s Python omni-completion (runtime/autoload/python3complete.vim and the legacy pythoncomplete.vim) executes reconstructed function and class definitions from the current buffer with exec() as part of populating the completion dictionary. When reconstructing that source, each scope-s docstring is inserted verbatim between triple quotes with no escaping, so a hostile buffer can break out of the triple-quoted literal and execute attacker-controlled Python during omni-completion. This vulnerability is fixed in 9.2.0699.

CVSS 7.8EPSS 0.145%Risque 0.79
Voir la source
Publication
2026-06-25 16:16:42
Versions concernées
<9.2.0699
Type
Logiciel critique
Vecteur
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H