Stats Digest Feeds
โ† Back to all CVEs

CVE-2026-43961

HIGH NVD
CVSS Score 7.8
Severity HIGH
Published Aug 19, 2026
Vendor unknown

Description

A flaw was found in Vim's netrw plugin. A crafted filename containing quote characters and expression fragments can break out of the quoted context during mark/unmark operations, allowing arbitrary Vimscript execution. This can be leveraged to run shell commands with the privileges of the user running Vim.

References