Bug 2486174 (CVE-2026-11487) - CVE-2026-11487 neovim: Neovim: Command Injection via argument path manipulation in M.read function
Summary: CVE-2026-11487 neovim: Neovim: Command Injection via argument path manipulati...
Keywords:
Status: NEW
Alias: CVE-2026-11487
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
high
high
Target Milestone: ---
Assignee: Product Security DevOps Team
QA Contact:
URL:
Whiteboard:
Depends On: 2486511 2486512
Blocks:
TreeView+ depends on / blocked
 
Reported: 2026-06-08 05:01 UTC by OSIDB Bzimport
Modified: 2026-06-08 18:42 UTC (History)
0 users

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description OSIDB Bzimport 2026-06-08 05:01:19 UTC
A flaw has been found in Neovim up to 0.12.2. Affected by this issue is the function M.read of the file runtime/lua/vim/secure.lua of the component View Branch. Executing a manipulation of the argument path can lead to command injection. It is possible to launch the attack on the local host. The exploit has been published and may be used. This patch is called f83e0dcaf8cf18de94828341b0a1a61a86c75baf. A patch should be applied to remediate this issue.


Note You need to log in before you can comment on or make changes to this bug.