PT-2026-29096 · Vim · Vim

Published

2026-03-30

·

Updated

2026-03-30

·

CVE-2026-34714

CVSS v3.1

9.2

Critical

AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:L
Vim before 9.2.0272 allows code execution that happens immediately upon opening a crafted file in the default configuration, because %{expr} injection occurs with tabpanel lacking P MLE.

Fix

OS Command Injection

Weakness Enumeration

Related Identifiers

CVE-2026-34714

Affected Products

Vim