Medium severity5.0NVD Advisory· Published Apr 8, 2026· Updated Apr 22, 2026
CVE-2026-39881
CVE-2026-39881
Description
Vim is an open source, command line text editor. Prior to 9.2.0316, a command injection vulnerability in Vim's netbeans interface allows a malicious netbeans server to execute arbitrary Ex commands when Vim connects to it, via unsanitized strings in the defineAnnoType and specialKeys protocol messages. This vulnerability is fixed in 9.2.0316.
Affected products
1Patches
17ab76a86048ehttps://github.com/vim/vimvia nvd-ref
Vulnerability mechanics
Generated by null/stub on May 9, 2026. Inputs: CWE entries + fix-commit diffs from this CVE's patches. Citations validated against bundle.
References
3- github.com/vim/vim/commit/7ab76a86048ed492374ac6b19nvdPatch
- github.com/vim/vim/security/advisories/GHSA-mr87-rhgv-7pw6nvdVendor Advisory
- github.com/vim/vim/releases/tag/v9.2.0316nvdRelease Notes
News mentions
0No linked articles in our index yet.