VDB
ALPINE-CVE-2026-34714
ALPINE-CVE-2026-34714
PUBLISHED
CVSS 8.600000381469727 HIGH
Vim before 9.2.0272 allows code execution that happens immediately upon opening a crafted file in the default configuration, because %{expr} injection occurs with tabpanel lacking P_MLE.
Risk Scores
CVSS v3.1
8.600000381469727
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Alpine:v3.23 | vim | 8.1.0829-r1, 0, 7.2.394-r1 |
Timeline
- Mar 30, 2026 CVE Published
- Apr 3, 2026 CVE Updated
- Apr 30, 2026 Distribution Patch