PT-2026-29480 · Vim+4 · Vim+4
Avishayy
·
Published
2026-03-31
·
Updated
2026-05-24
·
CVE-2026-34982
CVSS v3.1
8.2
High
| Vector | AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
Vim versions prior to 9.2.0276
Description
Vim is susceptible to remote code execution through maliciously crafted "modelines" that can bypass sandboxes. This allows for the execution of commands.
Recommendations
Update to version 9.2.0276 or add "set nomodeline" to your vimrc.
Fix
RCE
OS Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Linuxmint
Red Os
Rocky Linux
Ubuntu
Vim