CRITICAL🇵🇱 Wersja polska

CVE-2026-34714

CVSS 9.2v3.1pub. 2026-03-30upd. 2026-09-01

Vim before 9.2.0272 allows code execution that happens immediately upon opening a crafted file in the default configuration, because %{expr} injection occurs with tabpanel lacking P_MLE.

🤖 AI Analysis
How it works

An attacker prepares a specially crafted file that immediately executes embedded code when opened in Vim. The mechanism relies on injecting an expression through the %{expr} sequence in the tabpanel configuration. The missing P_MLE flag means that this option is not restricted to command-line mode, allowing arbitrary expressions to be executed in the default editor configuration.

Impact

An attacker can execute arbitrary code on the victim's system (RCE) when opening a file, potentially taking control of the system with Vim process privileges. Due to the scope of impact (Scope: Changed), the consequences may extend beyond the editor process itself.

Mitigation & patch

Vim should be updated to version 9.2.0272 or later. The patch is available in the official GitHub repository (tag v9.2.0272, commit 664701eb7576edb7c7c7d9f2d600815ec1f43459). Until updating, it is recommended to be cautious when opening files from untrusted sources.

Who is affected

Vim versions prior to 9.2.0272

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:L
  • Vim

    APP
    Vim
    9.1.1390 – 9.2.0272 (excl.)
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
RCECommand Injection
CWE
References

Related vulnerabilities

CVE-2020-20703CRITICAL9.8PL ✓same product

Buffer Overflow w VIM 8.1.2135 umożliwiający zdalne wykonanie kodu

CVE-2022-3520CRITICAL9.8PL ✓same product

Przepełnienie bufora na stercie (heap buffer overflow) w edytorze Vim

CVE-2022-0318CRITICAL9.8PL ✓same product

Heap-based Buffer Overflow w Vim — przepełnienie sterty przed wersją 8.2

CVE-2017-6349CRITICAL9.8PL ✓same product

Integer overflow w Vim podczas odczytu uszkodzonego pliku undo

CVE-2017-6350CRITICAL9.8PL ✓same product

Przepełnienie liczby całkowitej w Vim przy odczycie uszkodzonego pliku undo