PT-2026-31445 · Vim+3 · Vim+3

CVE-2026-39881

·

Published

2026-04-08

·

Updated

2026-06-29

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Vim versions prior to 9.2.0316
Description A command injection issue exists in Vim's netbeans interface. A malicious netbeans server can execute arbitrary Ex commands when Vim connects to it, due to unsanitized strings in the defineAnnoType and specialKeys protocol messages.
Recommendations Update to version 9.2.0316 or later.

Exploit

Fix

Code Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-09835
CVE-2026-39881
ECHO-49A6-CBE4-2CF6
GHSA-MR87-RHGV-7PW6
OESA-2026-2003
OESA-2026-2004
OESA-2026-2005
OESA-2026-2006
OESA-2026-2007
OPENSUSE-SU-2026:10652-1
OPENSUSE-SU-2026:20828-1
SUSE-SU-2026:1764-1
SUSE-SU-2026:2029-1
SUSE-SU-2026:21414-1
SUSE-SU-2026:21450-1
SUSE-SU-2026:21833-1
SUSE-SU-2026:21840-1
SUSE-SU-2026:21859-1
SUSE-SU-2026:2313-1
USN-8213-1
USN-8246-1

Affected Products

Linuxmint
Red Os
Ubuntu
Vim