VYPR
Critical severity9.2NVD Advisory· Published Mar 30, 2026· Updated Apr 3, 2026

CVE-2026-34714

CVE-2026-34714

Description

Vim before 9.2.0272 allows code execution that happens immediately upon opening a crafted file in the default configuration, because %{expr} injection occurs with tabpanel lacking P_MLE.

Affected products

1
  • cpe:2.3:a:vim:vim:*:*:*:*:*:*:*:*
    Range: <9.2.0272

Patches

1
664701eb7576

Vulnerability mechanics

Generated by null/stub on May 9, 2026. Inputs: CWE entries + fix-commit diffs from this CVE's patches. Citations validated against bundle.

References

7

News mentions

0

No linked articles in our index yet.