logo

Vim Modeline Vulnerability: How a Crafted File Can Hijack Your System

ID: 96705a86-bb77-589d-9ca0-e7d38ae89795

STIX ID: report--96705a86-bb77-589d-9ca0-e7d38ae89795

Feed Name: securityonline.info

Threat Score
75/100

Date Published: 2026-04-01

Date Updated: 2026-04-23

Author: Ddos

...
...

The Vim project disclosed CVE-2026-34982, a high-severity modeline sandbox bypass (CVSS 8.2) affecting all Vim versions prior to 9.2.0276. Missing security flags on options such as complete, guitabtooltip, and printheader allow modelines to execute code; combined with a lack of check_secure() in mapset(), an attacker can achieve arbitrary command execution with the privileges of the user opening a crafted file. Users are advised to update to Vim 9.2.0276 or later.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.