PT-2026-48721 · Vim+2 · Vim+2

·

CVE-2026-52858

·

Published

2026-06-11

·

Updated

2026-07-16

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Vim versions prior to 9.2.0561
Description The Python omni-completion script in python3complete.vim (for builds with the +python3 interpreter enabled) and pythoncomplete.vim (for builds with the +python interpreter) executes import and from statements found in the current buffer using Python's import machinery. Since the buffer's working directory is included in sys.path, opening a malicious .py file that has a sibling Python package and triggering omni-completion allows the top-level code of that package to be executed with the privileges of the user editing the file.
Recommendations Update to version 9.2.0561.

Exploit

Fix

Code Injection

Eval Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-52858
ECHO-C2A9-CB6F-D4B0
GHSA-52MC-RQ6P-RC7C
OESA-2026-2863
USN-8451-1

Affected Products

Linuxmint
Ubuntu
Vim