Bug 2514065 (CVE-2026-73077)
| Summary: | CVE-2026-73077 vim: Vim: Arbitrary Code Execution via Insecure Shell Command Handling | ||
|---|---|---|---|
| Product: | [Other] Security Response | Reporter: | OSIDB Bzimport <bzimport> |
| Component: | vulnerability | Assignee: | Product Security <prodsec-ir-bot> |
| Status: | NEW --- | QA Contact: | |
| Severity: | high | Docs Contact: | |
| Priority: | high | ||
| Version: | unspecified | CC: | kshier, rhel-process-autobot, stcannon, teagle, watson-tool-maintainers, yguenane |
| Target Milestone: | --- | Keywords: | Security |
| Target Release: | --- | ||
| Hardware: | All | ||
| OS: | Linux | ||
| Whiteboard: | |||
| Fixed In Version: | Doc Type: | --- | |
| Doc Text: |
A flaw was found in Vim, an open-source command-line text editor. The filetype plugins for shell scripts (sh.vim, zsh.vim, ps1.vim) insecurely handle Visual-mode selections, allowing an attacker to inject and execute arbitrary operating-system commands. This occurs because shell metacharacters are not properly neutralized before invoking external shell commands, leading to arbitrary code execution with the privileges of the user running Vim. Exploitation requires user interaction, where a victim deliberately selects crafted text in Visual mode and invokes the keyword lookup.
|
Story Points: | --- |
| Clone Of: | Environment: | ||
| Last Closed: | Type: | --- | |
| Regression: | --- | Mount Type: | --- |
| Documentation: | --- | CRM: | |
| Verified Versions: | Category: | --- | |
| oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
| Cloudforms Team: | --- | Target Upstream Version: | |
| Embargoed: | |||
|
Description
OSIDB Bzimport
2026-08-11 16:11:48 UTC
|