Beveiligingsadvies

CVE-2026-33412

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2026-03-24 19:43:07
Laatst bijgewerkt 2026-09-01 12:04:49
Toegewezen door GitHub_M
CVSS-score 5.6
Status PUBLISHED

Beschrijving

Vim is an open source, command line text editor. Prior to version 9.2.0202, a command injection vulnerability exists in Vim's glob() function on Unix-like systems. By including a newline character (\n) in a pattern passed to glob(), an attacker may be able to execute arbitrary shell commands. This vulnerability depends on the user's 'shell' setting. This issue has been patched in version 9.2.0202.