High severityNVD Advisory· Published Aug 11, 2026
CVE-2026-73076
CVE-2026-73076
Description
Vim is an open source, command line text editor. Prior to 9.2.0847, runtime/autoload/vimball.vim allows a crafted vimball member named .VimballRecord to overwrite the installation record with attacker-chosen commands. When vimball#RmVimball() later processes the matching record entry, the stored Ex commands, including operating-system commands invoked through :!, execute with the privileges of the user running Vim. This issue is fixed in version 9.2.0847.
Affected products
1Patches
Vulnerability mechanics
References
2News mentions
0No linked articles in our index yet.