VYPR
High severity7.8NVD Advisory· Published Jun 25, 2026· Updated Jun 26, 2026

CVE-2026-55895

CVE-2026-55895

Description

Vim is an open source, command line text editor. Prior to 9.2.0663, a Vimscript code injection vulnerability exists in s:NetrwLocalRmFile() in the netrw plugin (runtime/pack/dist/opt/netrw/autoload/netrw.vim) when deleting a local file from the browser. A filename derived from the buffer's directory listing is interpolated into an Ex command line passed to :execute with only the backslash character escaped, allowing a crafted filename containing a bar (|) to terminate the intended command and execute arbitrary Vimscript, including shell commands via :call system() and :!. This vulnerability is fixed in 9.2.0663.

Affected products

2
  • Vim/Vim2 versions
    cpe:2.3:a:vim:vim:*:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:vim:vim:*:*:*:*:*:*:*:*range: <9.2.0663
    • (no CPE)range: <9.2.0663

Patches

Vulnerability mechanics

References

3

News mentions

0

No linked articles in our index yet.