VDB
CVE-2026-44656
CVE-2026-44656
PUBLISHED
CVSS 4.599999904632568 MEDIUM
Vim is an open source, command line text editor. Prior to version 9.2.0435, an OS command injection vulnerability exists in Vim's :find command-line completion. When the path option contains backtick-enclosed shell commands, those commands are executed during file name completion. Because the path option lacks the P_SECURE flag, it can be set from a modeline, allowing an attacker who controls the contents of a file to execute arbitrary shell commands when the user opens that file in Vim and triggers :find completion. This issue has been patched in version 9.2.0435.
EPSS 0.07% · 20.9th percentile
Risk Scores
CVSS v4.0
4.599999904632568
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N
EPSS Score
0.07%
20.9th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| vim | vim | < 9.2.0435 |
Timeline
- May 8, 2026 CVE Published
- May 10, 2026 Security Advisory
- May 13, 2026 Security Advisory
- May 13, 2026 Security Advisory
- May 13, 2026 Security Advisory
- May 13, 2026 Security Advisory
- May 13, 2026 Security Advisory
- May 13, 2026 Security Advisory
- May 13, 2026 Security Advisory
- May 13, 2026 Security Advisory
- May 13, 2026 Security Advisory
- May 13, 2026 Security Advisory
References
- https://github.com/vim/vim/security/advisories/GHSA-hwg5-3cxw-wvvg url
- https://github.com/vim/vim/commit/190cb3c2b9c769a3972bcfd991a7b5b6cb771ef0 url
- https://github.com/vim/vim/releases/tag/v9.2.0435 url
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-33110 advisory
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-6664 advisory
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-32185 advisory
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-41602 advisory
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45130 advisory
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-48431 advisory
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-6665 advisory
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-41103 advisory
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-35439 advisory
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-32177 advisory
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-41610 advisory
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-40417 advisory
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42898 advisory
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-41614 advisory
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-41612 advisory
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-40374 advisory
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-41636 advisory
…and 17 more