A flaw was found in Vim's netrw plugin. A crafted filename containing quote characters and expression fragments can break out of the quoted context during mark/unmark operations, allowing arbitrary Vimscript execution. This can be leveraged to run shell commands with the privileges of the user running Vim.
References
Configurations
No configuration.
History
No history.
Information
Published : 2026-08-19 14:17
Updated : 2026-09-01 09:16
NVD link : CVE-2026-43961
Mitre link : CVE-2026-43961
CVE.ORG link : CVE-2026-43961
JSON object : View
Products Affected
No product.
CWE
CWE-94
Improper Control of Generation of Code ('Code Injection')
