PT-2026-29096 · Vim+1 · Vim+1

Christian Brabandt

·

Published

2026-01-01

·

Updated

2026-05-24

·

CVE-2026-34714

CVSS v3.1

9.2

Critical

VectorAV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:L
Name of the Vulnerable Software and Affected Versions: Vim versions prior to 9.2.0272.
Description: Vim versions prior to 9.2.0272 contain a flaw that allows for code execution upon opening a crafted file in the default configuration. This is due to a %{expr} injection occurring within the tabpanel when it lacks P MLE. Reports indicate that attackers are actively exploiting this vulnerability (CVE-2026-34714) to achieve Remote Code Execution (RCE) through malicious %{expr} injections in crafted files. The vulnerability was discovered by Claude AI. There have been real-world incidents of exploitation, with attackers achieving RCE by simply opening a malicious file. The vulnerability affects the tabpanel component and involves the injection of code through the %{expr} mechanism. The API endpoint is not explicitly mentioned, but the vulnerability is triggered by opening a file with a crafted payload.
Recommendations: Update Vim to version 9.2.0272 or newer immediately. Avoid opening files from untrusted sources.

Fix

RCE

OS Command Injection

Weakness Enumeration

Related Identifiers

BDU:2026-05833
CVE-2026-34714
ECHO-D746-10AA-D3E5
MGASA-2026-0077
OPENSUSE-SU-2026:10652-1
OPENSUSE-SU-2026:20540-1
SUSE-SU-2026:1347-1
SUSE-SU-2026:1387-1
SUSE-SU-2026:1607-1
SUSE-SU-2026:21118-1
SUSE-SU-2026:21124-1
SUSE-SU-2026:21134-1
SUSE-SU-2026:21197-1

Affected Products

Red Os
Vim