CVE-2019-20807

MEDIUM

Vim < 8.1.0881 - OS Command Injection

Title source: rule

Description

In Vim before 8.1.0881, users can circumvent the rvim restricted mode and execute arbitrary OS commands via scripting interfaces (e.g., Python, Ruby, or Lua).

Scores

CVSS v3 5.3
EPSS 0.0021
EPSS Percentile 42.6%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L

Classification

CWE
CWE-78
Status published

Affected Products (9)

vim/vim < 8.1.0881
debian/debian_linux
opensuse/leap
canonical/ubuntu_linux
canonical/ubuntu_linux
apple/mac_os_x
apple/mac_os_x
starwindsoftware/command_center
starwindsoftware/san_\&_nas

Timeline

Published May 28, 2020
Tracked Since Feb 18, 2026