Home

Description

Vim before 9.2.0272 allows code execution that happens immediately upon opening a crafted file in the default configuration, because %{expr} injection occurs with tabpanel lacking P_MLE.

PUBLISHED Reserved 2026-03-30 | Published 2026-03-30 | Updated 2026-04-03 | Assigner mitre




CRITICAL: 9.2CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:L

Problem types

CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

Product status

Default status
unaffected

Any version before 9.2.0272
affected

References

www.openwall.com/lists/oss-security/2026/04/02/4

www.openwall.com/lists/oss-security/2026/04/02/5

www.openwall.com/lists/oss-security/2026/04/03/6

www.openwall.com/lists/oss-security/2026/03/30/3

github.com/vim/vim/security/advisories/GHSA-2gmj-rpqf-pxvh

github.com/...ommit/664701eb7576edb7c7c7d9f2d600815ec1f43459

github.com/vim/vim/releases/tag/v9.2.0272

cve.org (CVE-2026-34714)

nvd.nist.gov (CVE-2026-34714)

Download JSON