CVE-2026-34982High· 8.2▾ TwilightVim is an open source, command line text editor. Prior to version 9.2.0276, a modeline sandbox bypass in Vim allows arbitrary OS command execution when a user opens a crafted file. The `complete`, `guitabtooltip` and `printheader` option…
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 45.1 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Stakeholder-Specific Vulnerability Categorization from CISA's ADP record at CVE.org: whether exploitation is observed, whether an attack can be automated, and how much of the system is at stake.
Exploit-prediction probability, daily snapshots since Jul 4.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
0.5%
Last analysed / modified upstream
Vim is an open source, command line text editor. Prior to version 9.2.0276, a modeline sandbox bypass in Vim allows arbitrary OS command execution when a user opens a crafted file. The complete, guitabtooltip and printheader options are missing the P_MLE flag, allowing a modeline to be executed. Additionally, the mapset() function lacks a check_secure() call, allowing it to be abused from sandboxed expressions. Commit 9.2.0276 fixes the issue.
vim < 9.2.0276Upgrade past the affected range:
vim 9.2.0276Connected by shared product, vendor, weakness, or advisory.
CVE-2026-47162High· 8.8Vim is an open source, command line text editor
CVE-2026-73076High· 8.4Vim is an open source, command line text editor
CVE-2026-73077High· 8.4Vim is an open source, command line text editor
CVE-2026-73078High· 8.6Vim is an open source, command line text editor
CVE-2026-43961High· 7.8A flaw was found in Vim's netrw plugin
CVE-2026-52860High· 7.8Vim is an open source, command line text editor