PT-2026-35033 · Vim+4 · Vim+4

·

CVE-2026-41411

·

Published

2026-04-24

·

Updated

2026-06-29

CVSS v3.1

6.6

Medium

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:L/I:H/A:L
Name of the Vulnerable Software and Affected Versions Vim versions prior to 9.2.0357
Description Command injection occurs during tag file processing. When resolving a tag, the filename field from the tags file undergoes wildcard expansion to resolve environment variables and wildcards. If this field contains backtick syntax, such as command, the embedded command is executed via the system shell with the full privileges of the running user.
Recommendations Update to version 9.2.0357 or later.

Exploit

Fix

OS Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2026:28209
ALSA-2026:28210
ALSA-2026:28553
BDU:2026-09836
CVE-2026-41411
ECHO-C375-87D8-EE8B
GHSA-CWGX-GCJ7-6QH8
OESA-2026-2201
OESA-2026-2202
OESA-2026-2203
OESA-2026-2204
OESA-2026-2297
RHSA-2026:28209
RHSA-2026:28210
RHSA-2026:28553
RHSA-2026:33453
RHSA-2026:34476
RHSA-2026:34477
USN-8246-1
USN-8342-1

Affected Products

Linuxmint
Red Os
Rocky Linux
Ubuntu
Vim