VDB

ALPINE-CVE-2026-34714

ALPINE-CVE-2026-34714 PUBLISHED CVSS 8.600000381469727 HIGH

Vim before 9.2.0272 allows code execution that happens immediately upon opening a crafted file in the default configuration, because %{expr} injection occurs with tabpanel lacking P_MLE.

Risk Scores

CVSS v3.1
8.600000381469727
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H

Affected Products

VendorProductVersions
Alpine:v3.23vim8.1.0829-r1, 0, 7.2.394-r1

Timeline

  • Mar 30, 2026 CVE Published
  • Apr 3, 2026 CVE Updated
  • Apr 30, 2026 Distribution Patch
Open in Interactive Console →
$ Console Community · 100/wk Open console ›