PT-2026-31445 · Vim+2 · Vim+2

Published

2026-04-08

·

Updated

2026-05-07

·

CVE-2026-39881

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Vim versions prior to 9.2.0316
Description A command injection issue exists in Vim's netbeans interface. A malicious netbeans server can execute arbitrary Ex commands when Vim connects to it, due to unsanitized strings in the defineAnnoType and specialKeys protocol messages.
Recommendations Update to version 9.2.0316 or later.

Fix

Code Injection

Weakness Enumeration

Related Identifiers

CVE-2026-39881
ECHO-49A6-CBE4-2CF6
OESA-2026-2003
OESA-2026-2004
OESA-2026-2005
OESA-2026-2006
OESA-2026-2007
OPENSUSE-SU-2026:10652-1
USN-8213-1
USN-8246-1

Affected Products

Linuxmint
Ubuntu
Vim