CVE-2026-73078Disclosure

LOWCVSS 8.6 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Vim is an open source, command line text editor. Prior to 9.2.0840, runtime/plugin/netrwPlugin.vim loads netrw and runtime/pack/dist/opt/netrw/autoload/netrw.vim constructs Bookmarks, History, and Targets menu entries by interpolating attacker-controlled directory paths into executed :menu commands. s:NetrwBookmarkMenu(), s:NetrwTgtMenu(), g:netrw_menu_escape, EX_TRLBAR, and netrw#MakeTgt() fail to neutralize the | command separator or single quotes at five construction sites, allowing a crafted path browsed or bookmarked in GUI Vim to execute arbitrary Ex and operating-system commands. This issue is fixed in version 9.2.0840.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-77CWE-184

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Threat summary

  • Patch or workaround signal is available
  • 1 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 1 signal
  • Disclosure: 1 classified signal
  • 1 total mentions across 1 day

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-08-11: 1Patch / Workaround · 2026-08-11: 1Technical Details · 2026-08-11: 108-11
Signal classification1 categories
Disclosure
1100.0%
Full discourse1 post
  • Upwind Security MDR@UpwindMDR
    Disclosure

    🚨High - Vim netrw Command Injection via Crafted Directory Paths (CVE-2026-73078) In Vim before 9.2.0840, the netrw file browser builds Bookmarks, History, and Targets menu entries by interpolating attacker-controlled directory paths into executed :menu commands. Five construction sites fail to neutralize the | command separator and single quotes, so a crafted path that is browsed or bookmarked in GUI Vim can execute arbitrary Ex and operating-system commands. The payload can be delivered in something as simple as a directory with a malicious name, but it requires the user to actively browse or bookmark that path in GUI Vim, so it is not fully automatic. The impact when it triggers is full command execution. 👉Upgrade Vim to 9.2.0840.

    Post summary

    A high‑severity command injection vulnerability in Vim’s netrw file browser has been disclosed, allowing attackers to execute arbitrary commands via specially crafted directory names; users are urged to upgrade to Vim 9.2.0840 to remediate.

    0000056
    285 followersView on X

Explore more