Code Execution Vulnerability in Vim by Vim
CVE-2026-34714

9.2CRITICAL

Key Information:

Vendor

Vim

Status
Vendor
CVE Published:
30 March 2026

What is CVE-2026-34714?

A vulnerability in Vim allows for arbitrary code execution upon opening a specially crafted file in the default configuration. This risk is due to the improper handling of expressions that allows for injection via the %{expr} feature when tabpanel configurations do not include P_MLE. Users of Vim prior to version 9.2.0272 should upgrade to the latest version to mitigate this security risk effectively.

Affected Version(s)

Vim 0 < 9.2.0272

References

CVSS V3.1

Score:
9.2
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.