← Vulnerability feed

Vulnerability record · CVE-2026-34982 · published 6 April 2026

CVE-2026-34982: Vim os command injection vulnerability

Vim · Vim

Vim is an open source, command line text editor. Prior to version 9.2.0276, a modeline sandbox bypass in Vim allows arbitrary OS command execution when a user opens a crafted file. The `complete`, `guitabtooltip` and `printheader` options are missing the `P_MLE` flag, allowing a modeline to be executed. Additionally, the `mapset()` function lacks a `check_secure()` call, allowing it to be abused from sandboxed expressions. Commit 9.2.0276 fixes the issue.

8.2 CVSS 3.1 High EPSS 0.27% · top 82.7% CWE-78 · OS command injection
8.2CVSS 3.1 base score
0.27%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
38References
18 Sep 2026Last modified by NVD

Description

Vim is an open source, command line text editor. Prior to version 9.2.0276, a modeline sandbox bypass in Vim allows arbitrary OS command execution when a user opens a crafted file. The `complete`, `guitabtooltip` and `printheader` options are missing the `P_MLE` flag, allowing a modeline to be executed. Additionally, the `mapset()` function lacks a `check_secure()` call, allowing it to be abused from sandboxed expressions. Commit 9.2.0276 fixes the issue.

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
https://github.com/vim/vim/commit/75661a66a1db1e1f3f1245c615 Patch
https://github.com/vim/vim/releases/tag/v9.2.0276 Release Notes
https://github.com/vim/vim/security/advisories/GHSA-8h6p-m6gr-mpw9 PatchVendor Advisory
http://www.openwall.com/lists/oss-security/2026/04/01/1 Mailing ListPatchThird Party Advisory
https://access.redhat.com/errata/RHSA-2026:11389
https://access.redhat.com/errata/RHSA-2026:11509
https://access.redhat.com/errata/RHSA-2026:11510
https://access.redhat.com/errata/RHSA-2026:19073
https://access.redhat.com/errata/RHSA-2026:19224
https://access.redhat.com/errata/RHSA-2026:21275
https://access.redhat.com/errata/RHSA-2026:22634
https://access.redhat.com/errata/RHSA-2026:28049
https://access.redhat.com/errata/RHSA-2026:28050
https://access.redhat.com/errata/RHSA-2026:28133
https://access.redhat.com/errata/RHSA-2026:30078
https://access.redhat.com/errata/RHSA-2026:30087
https://access.redhat.com/errata/RHSA-2026:30088
https://access.redhat.com/errata/RHSA-2026:30089
https://access.redhat.com/errata/RHSA-2026:30900
https://access.redhat.com/errata/RHSA-2026:33453
https://access.redhat.com/errata/RHSA-2026:34476
https://access.redhat.com/errata/RHSA-2026:34477
https://access.redhat.com/errata/RHSA-2026:36004
https://access.redhat.com/errata/RHSA-2026:36005
https://access.redhat.com/errata/RHSA-2026:36006
https://access.redhat.com/errata/RHSA-2026:56786
https://access.redhat.com/errata/RHSA-2026:56853
https://access.redhat.com/errata/RHSA-2026:56911
https://access.redhat.com/errata/RHSA-2026:57402
https://access.redhat.com/errata/RHSA-2026:57483
https://access.redhat.com/errata/RHSA-2026:58981
https://access.redhat.com/errata/RHSA-2026:59831
https://access.redhat.com/errata/RHSA-2026:60019
https://access.redhat.com/errata/RHSA-2026:65839
https://access.redhat.com/errata/RHSA-2026:68711
https://access.redhat.com/security/cve/CVE-2026-34982
https://bugzilla.redhat.com/show_bug.cgi?id=2455400
https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-34982.json

Track CVE-2026-34982 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2020-20703Vim classic buffer overflow vulnerabilityBuffer Overflow vulnerability in VIM v.8.1.2135 allows a remote attacker to execute arbitrary code via the operand parameter.EPSS 1.5%9.8CVE-2022-3520Vim heap-based buffer overflow vulnerabilityHeap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.0765.EPSS 1.0%9.8CVE-2022-0318Vim heap-based buffer overflow vulnerabilityHeap-based Buffer Overflow in vim/vim prior to 8.2.EPSS 2.0%9.8CVE-2017-6349Vim integer overflow vulnerabilityAn integer overflow at a u_read_undo memory allocation site would occur for vim before patch 8.0.0377, if it does not properly validate values for tr…EPSS 2.7%9.8CVE-2017-6350Vim integer overflow vulnerabilityAn integer overflow at an unserialize_uep memory allocation site would occur for vim before patch 8.0.0378, if it does not properly validate values f…EPSS 3.2%9.8CVE-2017-5953Vim integer overflow vulnerabilityvim before patch 8.0.0322 does not properly validate values for tree length when handling a spell file, which may result in an integer overflow at a …EPSS 2.8%9.3CVE-2008-6235Vim os command injection vulnerabilityThe Netrw plugin (netrw.vim) in Vim 7.0 and 7.1 allows user-assisted attackers to execute arbitrary commands via shell metacharacters in a filename u…EPSS 3.0%9.3CVE-2008-3074Tar.vim os command injection vulnerabilityThe shellescape function in Vim 7.0 through 7.2, including 7.2a.10, allows user-assisted attackers to execute arbitrary code via the "!" (exclamation…EPSS 3.8%

Source: NIST National Vulnerability Database (record CVE-2026-34982), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.