CVE-2026-43961

Discovered by AISLEPUBLISHEDCWE-94

Description

A flaw was found in Vim's netrw plugin. A crafted filename containing quote characters and expression fragments can break out of the quoted context during mark/unmark operations, allowing arbitrary Vimscript execution. This can be leveraged to run shell commands with the privileges of the user running Vim.

CVSS Base Scores

CVSS v3.1(Primary)
4.8

CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:L

Affected Products

VendorProductVersionStatus
vimvim0affected
Red HatRed Hat Hardened Images9.2.967-1.1.hum1unaffected
Red HatRed Hat Enterprise Linux 10——
Red HatRed Hat Enterprise Linux 6——
Red HatRed Hat Enterprise Linux 7——
Red HatRed Hat Enterprise Linux 8——
Red HatRed Hat Enterprise Linux 9——
Red HatRed Hat OpenShift Container Platform 4——

Credits

  • Red Hat would like to thank AISLE Research for reporting this issue.

References