CVE-2026-47162Patch(vim / vim)

LOWCVSS 8.8 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch vim vim systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Vim is an open source, command line text editor. Prior to version 9.2.0495, a Vimscript code injection vulnerability exists in s:NetrwBookHistSave() in the netrw plugin (runtime/pack/dist/opt/netrw/autoload/netrw.vim) when serializing browsed directory paths to the history file ~/.vim/.netrwhist. A directory name derived from the filesystem is interpolated into a single-quoted Vimscript string literal without escaping embedded single quotes, allowing a crafted directory name to break out of the string context and execute arbitrary Vimscript, including shell commands via system() and :!, the next time the history file is sourced. This issue has been patched in version 9.2.0495.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-74CWE-94CWE-140

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • vim

Threat summary

  • Patch or workaround signal is available
  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 1 signal
  • Disclosure: 1 classified signal
  • Peaked 1d ago at 1 mentions (2026-06-21); latest day: 1
  • 2 total mentions across 2 days

Affected systems

Vendors
Products
vim

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-06-21: 1Mentions · 2026-06-26: 1Patch / Workaround · 2026-06-21: 1Technical Details · 2026-06-21: 106-2106-26
Signal classification2 categories
Patch
150.0%
Disclosure
150.0%
Referenced assets1 URL
By indicator
Classification over time
DateTotalLabels
2026-06-211
Patch1
2026-06-261
Disclosure1
Full discourse2 posts
  • CERT-PY@CERTpy
    Disclosure

    ⚠️ Vulnerabilidades en productos Vim ❗ CVE-2026-52860 ❗ CVE-2026-52858 ❗ CVE-2026-47162 ➡️ Más info: https://www.cert.gov.py/vulnerabilidades-en-productos-vim/ https://t.co/5yypSywmeZ

    Post summary

    The announcement lists three CVEs (CVE‑2026‑52860, CVE‑2026‑52858, CVE‑2026‑47162) affecting Vim products and directs readers to a CERT advisory for further information.

    00011309
    6.7K followersView on X
  • Can Artuc@canartuc
    Patch

    The Vim project patched CVE-2026-47162 in the bundled netrw plugin (9.2.0495) and a PowerShell command injection in zip.vim triggered by crafted archive entry names (9.2.0678). Both ship in stock Vim. When did you last update the editor itself, not just plugins?

    Post summary

    The Vim project has patched CVE-2026-47162 in the netrw plugin (new version 9.2.0495) and fixed a PowerShell command injection in zip.vim (9.2.0678); users should update Vim to the latest release to remediate these vulnerabilities.

    0000142
    172 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appvimvim---

Explore more