CVE-2026-42307

MEDIUM

Vim netrw - OS Command Injection

Title source: manual
STIX 2.1

Description

Vim is an open source, command line text editor. Prior to version 9.2.0383, an OS command injection vulnerability exists in the netrw standard plugin bundled with Vim. By inducing a user to open a crafted URL (e.g., using the sftp:// or file:// protocol handlers), an attacker can execute arbitrary shell commands with the privileges of the Vim process. This issue has been patched in version 9.2.0383.

References (3)

Core 3

Scores

CVSS v3 4.4
EPSS 0.0023
EPSS Percentile 45.7%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-78
Status published
Products (1)
vim/vim < 9.2.0383 (2 CPE variants)
Published May 08, 2026
Tracked Since May 09, 2026