These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.
A flaw in Vim's netrw plugin allows arbitrary Vimscript execution via crafted filenames with quote characters and expression fragments during mark/unmark operations. This can lead to running shell commands with the privileges of the user running Vim. The vulnerability has a high CVSS score of 7.8 and is considered HIGH severity. Users of Vim should assess their exposure and apply patches or mitigations as [truncated]
CVE-2026-73073 is a high-severity vulnerability in Vim, a command-line text editor. The vulnerability exists in the StructMembers() function in runtime/autoload/ccomplete.vim, which constructs and executes a vimgrep command using an insufficiently escaped typeref: or typename: value from a tags file. This allows an attacker to execute arbitrary Ex and operating-system commands when a user invokes C omni-c [truncated]
CVE-2026-73078 is a high-severity vulnerability in Vim, a command-line text editor. The vulnerability exists in the netrw plugin, which allows attackers to execute arbitrary Ex and operating-system commands by crafting a malicious directory path. This issue is fixed in Vim version 9.2.0840. Defenders should prioritize updating to version 9.2.0840 or later to prevent exploitation of this vulnerability. The [truncated]
CVE-2026-73077 debrief based on the supplied source corpus. The vulnerability in Vim allows arbitrary operating-system commands to execute with user privileges. Affected product deployments should be verified, and patches applied to prevent potential arbitrary command execution. The CVE record and NVD entry provide details on the vulnerability, which is fixed in version 9.2.0839. Defenders should assess e [truncated]
CVE-2026-73076 is a high-severity vulnerability in Vim, a command-line text editor. The vulnerability exists in the vimball.vim file, which allows a crafted vimball member to overwrite the installation record with attacker-chosen commands. These commands can execute with the privileges of the user running Vim when vimball#RmVimball() processes the matching record entry.
A vulnerability in Vim, a command-line text editor, allows for an out-of-bounds read and conditional write due to improper handling of a negative w_winrow value in the popup_mark_opacity_zindex() function. This issue affects Vim versions from 9.2.0469 to 9.2.0842 and is fixed in version 9.2.0843. The vulnerability can be exploited by an attacker to potentially execute arbitrary code or cause a denial of s [truncated]
A vulnerability in Vim, a command-line text editor, allows for a heap-based buffer overflow when handling text properties. This issue, fixed in version 9.2.0841, has a CVSS score of 7.1 and is considered HIGH severity. The vulnerability arises from the prop_add_one() function in src/textprop.c, which incorrectly handles property counts, leading to potential denial of service or code execution. Defenders s [truncated]
CVE-2026-73072 is a high-severity vulnerability in Vim, a command-line text editor. The vulnerability exists in the set_sofo() function in src/spellfile.c, where it reuses sl_sal_first[] without resetting values left by set_sal_first(). This can cause under-counted mapping lists and allow an attacker to write beyond a heap allocation. The issue is fixed in version 9.2.0846.
A low-severity vulnerability exists in Vim, a command-line text editor, from version 9.2.0511 to 9.2.0844. The issue arises in the json_decode_item() function in src/json.c, which can retain a stale pointer after json_decode_string() invokes channel_fill() to refill and free the current buffer. This can cause the error path to read freed memory, leading to potential crashes or information disclosure.
A local process can connect to the Vim server socket, potentially corrupting stack memory or terminating the Vim server due to unbounded client connections accepted by the socket server backend prior to version 9.2.0842. This issue allows a local attacker to impact the Vim server, potentially leading to privilege escalation. Defenders should assess exposure, especially in local or shared environments, and [truncated]
CVE-2026-59858 is a high-severity vulnerability in Vim's C omni-completion script. This issue allows arbitrary Ex command execution when a hostile .c file with a crafted tag field is opened and C omni-completion is invoked. The vulnerability exists because the C omni-completion script interpolates the typeref: or typename: extension field of a tags entry without escaping, into a :vimgrep pattern that is r [truncated]
A boundary-length word passed to soundfold() in Vim versions prior to 9.2.0725 can corrupt the eval_soundfold() stack frame and crash the editor. This issue is fixed in version 9.2.0725. The vulnerability affects Vim, a command line text editor, and has a medium severity with a CVSS score of 5.6. Users of Vim, especially those using version 9.2.0724 or earlier, should update to the latest version to preve [truncated]
CVE-2026-59856 is a high-severity vulnerability in Vim's PHP omni-completion script. This issue allows for arbitrary operating-system command execution when a victim opens a crafted PHP file and invokes omni-completion. The vulnerability is fixed in Vim version 9.2.0736. The vulnerability affects users of Vim, especially those working with PHP files. The vulnerability has a CVSS score of 8.4 and a CVSS se [truncated]
CVE-2026-52860 debrief: Vim's Python omni-completion feature executes reconstructed function and class definitions from the current buffer with exec(), allowing hostile buffers to execute attacker-controlled Python expressions. This issue is patched in version 9.2.0597. The vulnerability exists due to the execution of reconstructed function and class definitions from the current buffer with exec() as part [truncated]
CVE-2026-52859 is a MEDIUM severity vulnerability in Vim, a command-line text editor. The vulnerability exists in the update_snapshot() function, which can lead to a crash when a program's output is rendered inside a :terminal window. This issue has been patched in version 9.2.0565.
CVE-2026-52858 is a high-severity vulnerability in Vim's Python omni-completion script. The vulnerability exists in python3complete.vim for Vim with the +python3 interpreter enabled and in pythoncomplete.vim for builds with the +python interpreter. When a user opens a hostile .py file with a sibling Python package and invokes omni-completion, it runs that package's top-level code as the editing user. This [truncated]
A code injection vulnerability exists in s:stepmatch() in the cucumber filetype plugin (runtime/ftplugin/cucumber.vim) on Vim builds with +ruby support. Prior to version 9.2.0496, step-definition patterns read from .rb files under the repository's features/*/ or stories/*/ directories are embedded into a Ruby Kernel.eval argument without sufficient escaping. This allows a crafted pattern in an attacker-co [truncated]
A code injection vulnerability exists in Vim's Netrw plugin, specifically in the `s:NetrwBookHistSave()` function. This function is used to save the history of browsed directories to the `~/.vim/.netrwhist` file. The vulnerability occurs when directory names are not properly escaped, allowing an attacker to inject arbitrary Vimscript code, including shell commands, by manipulating the directory name.
A command injection vulnerability exists in Vim's tar plugin (tar#Vimuntar() in runtime/autoload/tar.vim) prior to version 9.2.0479. When decompressing .tgz archives on Unix-like systems, the function constructs :!gunzip and :!gzip -d commands using shellescape(tartail) without the {special} flag. This omission allows crafted archive filenames containing Vim cmdline-special characters to trigger expansion [truncated]
A heap buffer overflow vulnerability exists in Vim prior to version 9.2.0450, specifically in the `read_compound()` function within `src/spellfile.c`. The flaw occurs when loading a crafted spell file (.spl) with UTF-8 encoding active. An attacker-controlled length field in the spell file's compound section can overflow a 32-bit signed integer multiplication, resulting in a small buffer allocation that is [truncated]
CVE-2026-35177 is a MEDIUM severity vulnerability in Vim's zip.vim plugin. Prior to 9.2.0280, a path traversal bypass allows overwriting of arbitrary files when opening specially crafted zip archives. This vulnerability is fixed in 9.2.0280. The vulnerability has a CVSS score of 4.1 and is considered a significant risk for users of affected Vim versions. Users of Vim versions prior to 9.2.0280 who handle [truncated]
CVE-2026-34982 is a high-severity vulnerability in Vim, a popular open-source text editor. The vulnerability allows for arbitrary OS command execution when a user opens a crafted file. This is due to a modeline sandbox bypass issue. Specifically, the `complete`, `guitabtooltip`, and `printheader` options are missing the `P_MLE` flag, allowing a modeline to be executed. Furthermore, the `mapset()` function [truncated]
CVE-2026-33412 is a command injection vulnerability in Vim's glob() function on Unix-like systems. This vulnerability allows an attacker to execute arbitrary shell commands by including a newline character (n) in a pattern passed to glob(). The vulnerability's impact depends on the user's 'shell' setting. Vim version 9.2.0202 patches this issue. Users should update to this version or apply mitigations to [truncated]
A vulnerability was discovered in Vim, an open-source command-line text editor. The NFA regex compiler in Vim, versions from 9.1.0011 to before 9.2.0137, incorrectly handles a collection containing a combining character as the endpoint of a character range. This leads to a segmentation fault when nfa_max_width() traverses the compiled NFA. The issue is fixed in version 9.2.0137. The vulnerability has a CV [truncated]
A heap buffer overflow vulnerability exists in Vim's tag file resolution logic when processing the 'helpfile' option. The flaw is located in the get_tagfname() function in src/tag.c, where a user-controlled 'helpfile' option value is copied into a fixed-size heap buffer of MAXPATHL + 1 bytes (typically 4097 bytes) using an unsafe STRCPY() operation without bounds checking. This vulnerability affects Vim v [truncated]
CVE-2017-6350 is a critical Vim vulnerability affecting versions through 8.0.0377. According to NVD and the vendor-linked patch reference, an integer overflow in unserialize_uep can occur when Vim fails to validate tree length values while reading a corrupted undo file, which may lead to buffer overflows. The vulnerability was publicly recorded on 2017-02-27, and the NVD entry was later modified on 2026-0 [truncated]
CVE-2017-6349 is a critical Vim flaw in undo-file handling. A corrupted undo file can trigger an integer overflow during memory allocation in u_read_undo if tree-length values are not validated, which can lead to buffer overflows. The issue was published on 2017-02-27 and is fixed by the upstream patch referenced in the source corpus.
CVE-2017-5953 is a critical memory-corruption issue in Vim's spell-file handling. According to the NVD record and vendor references, Vim did not properly validate tree-length values, which could trigger an integer overflow at a memory-allocation site and then a resulting buffer overflow. The issue was publicly disclosed on 2017-02-10 and is rated CVSS 3.0 9.8 (network, low complexity, no privileges, no us [truncated]