CVE-2026-46483Patch(vim / vim)

LOWCVSS 7.0 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch vim vim systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Vim is an open source, command line text editor. Prior to 9.2.0479, a command injection vulnerability exists in tar#Vimuntar() in runtime/autoload/tar.vim when decompressing .tgz archives on Unix-like systems. The function builds :!gunzip and :!gzip -d commands using shellescape(tartail) without the {special} flag, allowing a crafted archive filename to trigger Vim cmdline-special expansion and execute shell commands in the user's context. This vulnerability is fixed in 9.2.0479.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-78CWE-88

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • vim

Threat summary

  • Patch or workaround signal is available
  • 3 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 3 signals
  • Disclosure: 1 classified signal
  • Peaked 2d ago at 1 mentions (2026-05-17); latest day: 1
  • 3 total mentions across 3 days

Affected systems

Vendors
Products
vim

Deep dive

Activity timeline3 mentions / 3d
00111Mentions · 2026-05-17: 1Mentions · 2026-05-27: 1Mentions · 2026-06-10: 1Patch / Workaround · 2026-05-27: 1Patch / Workaround · 2026-06-10: 1Technical Details · 2026-05-17: 1Technical Details · 2026-05-27: 1Technical Details · 2026-06-10: 105-1705-2706-10
Signal classification2 categories
Patch
266.7%
Disclosure
133.3%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-05-171
Disclosure1
2026-05-271
Patch1
2026-06-101
Patch1
Full discourse3 posts
  • ThreatCluster@threatcluster
    Patch

    Ubuntu issued security fixes for Vim to address CVE-2026-43961 and CVE-2026-46483, arbitrary code execution flaws affecting Ubuntu 14.04 through 26.04 LTS releases, according to security notice USN-8415-1. https://threatcluster.io/cluster/critical-code-execution-vulnerabilities-in-vim-affecting-mul-dc382f8a

    Post summary

    Ubuntu released patches for CVE-2026-43961 and CVE-2026-46483, which enable arbitrary code execution in Vim across multiple LTS releases, with no report of current exploitation or PoC.

    0000066
    318 followersView on X
  • WindowsForum@windowsforum
    Patch

    🐍 Another reminder: “just edit a file” can mean “run shell commands.” CVE-2026-46483 is why dev tooling is attack surface too—patch Vim, stop trusting random .tgz. #Windows #Security #Vim https://windowsforum.com/threads/cve-2026-46483-vim-tar-command-injection-patch-and-workflow-risk-guide.420050/?utm_source=x&utm_medium=social&utm_campaign=news_node84 #CommandInjection #VimSecurity #Cve202646483 #TarArchive https://t.co/dPrQpMkCgm

    Post summary

    The tweet announces the existence of CVE‑2026‑46483, a tar command‑injection flaw in Vim, and urges users to apply patches and avoid untrusted archives, without evidence of active exploitation or a provided PoC.

    0000074
    1.1K followersView on X
  • cybersecuritypath@cybrsecpath
    Disclosure

    Vim Vulnerability Alert: CVE-2026-46483 Command Injection in tar.vim https://thecybrdef.com/vim-cve-2026-46483-command-injection-vulnerability/ #Cyberupdates #Cybertechnews #Cybersecurity

    Post summary

    The post announces a newly identified Command Injection vulnerability (CVE-2026-46483) in Vim’s tar.vim script, but provides no details about exploits, patches, or PoC.

    0000060
    9 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appvimvim---

Explore more