Fedora Account System
Red Hat Associate
Red Hat Customer
Vim is an open source, command line text editor. Prior to 9.2.0699, Vim's Python omni-completion (runtime/autoload/python3complete.vim and the legacy pythoncomplete.vim) executes reconstructed function and class definitions from the current buffer with exec() as part of populating the completion dictionary. When reconstructing that source, each scope's docstring is inserted verbatim between triple quotes with no escaping, so a hostile buffer can break out of the triple-quoted literal and execute attacker-controlled Python during omni-completion. This vulnerability is fixed in 9.2.0699.
This issue has been addressed in the following products: Red Hat Enterprise Linux 9 Via RHSA-2026:47982 https://access.redhat.com/errata/RHSA-2026:47982
This issue has been addressed in the following products: Red Hat Enterprise Linux 8 Via RHSA-2026:48703 https://access.redhat.com/errata/RHSA-2026:48703
This issue has been addressed in the following products: Red Hat Enterprise Linux 10 Via RHSA-2026:48650 https://access.redhat.com/errata/RHSA-2026:48650