Vimscript Code Injection Vulnerability in Vim's netrw Plugin
CVE-2026-47162

7.3HIGH

Key Information:

Vendor

Vim

Status
Vendor
CVE Published:
11 June 2026

What is CVE-2026-47162?

A code injection vulnerability exists in the netrw plugin of Vim, which allows attackers to craft directory names that break out of string literals in Vimscript. This occurs in the s:NetrwBookHistSave() function when saving browsed directory paths to the history file. If triggered, the malicious directory name can execute arbitrary Vimscript or shell commands upon sourcing the history file at a later time. This vulnerability has been addressed in version 9.2.0495.

Affected Version(s)

vim < 9.2.0495

References

CVSS V4

Score:
7.3
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.