Security Advisory

CVE-2026-43961

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2026-08-19 14:06:09
Last updated 2026-08-19 16:53:18
Assigner redhat
CVSS score 7.8
State PUBLISHED

Description

A flaw was found in Vim's netrw plugin. A crafted filename containing quote characters and expression fragments can break out of the quoted context during mark/unmark operations, allowing arbitrary Vimscript execution. This can be leveraged to run shell commands with the privileges of the user running Vim.