Vim Under Fire: High-Severity “Tabpanel” Bug Allows RCE via Simple File Open
ID: c5147899-f700-5f7b-b077-8dab0907faad
STIX ID: report--c5147899-f700-5f7b-b077-8dab0907faad
Feed Name: securityonline.info
A critical Vim vulnerability (CWE-78, CVSS 8.2) can lead to arbitrary OS command execution when a user opens a specially crafted file: a modeline format-string option lacking the P_MLE security flag allows expression injection and a subsequent sandbox bypass in autocmd_add() registers a persistent malicious autocommand. Most standard Vim builds with +tabpanel are affected, and maintainers released an emergency patch (update to 9.2.0272) with a temporary mitigation to disable modelines (set nomodeline).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
