PT-2026-48707 · Vim+3 · Vim+3
CVSS v2.0
6.5
Medium
| Vector | AV:N/AC:L/Au:S/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Vim versions prior to 9.2.0496
Description
A code injection issue exists in the
s:stepmatch() function within the cucumber filetype plugin (runtime/ftplugin/cucumber.vim) for builds with +ruby support. Step-definition patterns read from .rb files in the features/*/ or stories/*/ directories are embedded into a Ruby Kernel.eval argument without sufficient escaping. This allows a crafted pattern in an attacker-controlled repository to execute arbitrary Ruby code and shell commands when a user invokes a step-jump mapping ([d, ]d).Recommendations
Update to version 9.2.0496.
Exploit
Fix
Code Injection
Eval Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Linuxmint
Red Os
Ubuntu
Vim