Vim is an open source, command line text editor. (CVE-2026-73077)
Description
Vim versions prior to 9.2.0839 contain a vulnerability in certain runtime filetype plugins that improperly handle attacker-controlled Visual-mode selections. This flaw allows shell metacharacters to be passed unsafely to shell commands, enabling arbitrary command execution with the privileges of the user running Vim. The issue affects multiple Ubuntu package versions of Vim and is fixed in version 9.2.0839.
CVSS v4.0
Affected software
pkg:deb/ubuntu/vim?arch=source&distro=jammypkg:deb/ubuntu/vim?arch=source&distro=noblepkg:deb/ubuntu/vim?arch=source&distro=resoluteRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
Vim's runtime filetype plugins for sh, zsh, and ps1 (sh.vim, zsh.vim, ps1.vim) prior to version 9.2.0839 pass attacker-controlled Visual-mode selections from the 'K' command through keywordprg commands without properly separating shell arguments. The functions fnameescape() and PATH_ESC_CHARS do not neutralize shell metacharacters before invoking bash, zsh, or PowerShell via ShKeywordPrg, ZshKeywordPrg, or GetHelp. This results in arbitrary operating system command execution with the privileges of the user running Vim. The vulnerability is resolved in Vim version 9.2.0839.
Potential Impact
An attacker able to control Visual-mode selections in Vim can execute arbitrary OS commands with the same privileges as the user running Vim. This could lead to unauthorized command execution and potential system compromise depending on user privileges.
Mitigation Recommendations
Upgrade Vim to version 9.2.0839 or later, where this vulnerability is fixed. No other mitigations are specified. Patch status is confirmed fixed in 9.2.0839.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- UBUNTU-CVE-2026-73077
- Osv Schema Version
- 1.7.0
- Ecosystems
- ["Ubuntu:22.04:LTS","Ubuntu:24.04:LTS","Ubuntu:26.04:LTS"]
- Cvss Version
- 4.0
Threat ID: 6a870a76acd9273b49b58b06
Added to database: 08/20/2026, 14:08:54 UTC
Last enriched: 08/20/2026, 14:32:47 UTC
Last updated: 10/05/2026, 06:48:18 UTC
Views: 42
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.