CVE-2026-43961
HIGH
NVD
CVSS Score
7.8
Severity
HIGH
Published
Aug 19, 2026
Vendor
unknown
Description
A flaw was found in Vim's netrw plugin. A crafted filename containing quote characters and expression fragments can break out of the quoted context during mark/unmark operations, allowing arbitrary Vimscript execution. This can be leveraged to run shell commands with the privileges of the user running Vim.