Vim before 9.2.0272 allows code execution that happens immediately upon opening a crafted file in the default configuration, because %{expr} injection occurs with tabpanel lacking P_MLE.
References
Configurations
History
No history.
Information
Published : 2026-03-30 19:16
Updated : 2026-09-01 13:18
NVD link : CVE-2026-34714
Mitre link : CVE-2026-34714
CVE.ORG link : CVE-2026-34714
JSON object : View
Products Affected
vim
- vim
