VYPR
High severity7.8NVD Advisory· Published Aug 19, 2026· Updated Aug 19, 2026

CVE-2026-43961

CVE-2026-43961

Description

A flaw was found in Vim's netrw plugin. A crafted filename containing quote characters and expression fragments can break out of the quoted context during mark/unmark operations, allowing arbitrary Vimscript execution. This can be leveraged to run shell commands with the privileges of the user running Vim.

Affected products

9

Patches

Vulnerability mechanics

References

4

News mentions

0

No linked articles in our index yet.