CVE-2026-34714

Publication date

2026-03-30 18:27:55

Family

mitre

State

PUBLISHED

Description

Vim before 9.2.0272 allows code execution that happens immediately upon opening a crafted file in the default configuration, because %{expr} injection occurs with tabpanel lacking P_MLE.