Back

HIGH

Vim: Arbitrary Command Execution via Malicious `.VimballRecord` Entry Replay in `vimball.vim`

Published Aug 11, 2026

Description

Vim is an open source, command line text editor. Prior to 9.2.0847, runtime/autoload/vimball.vim allows a crafted vimball member named .VimballRecord to overwrite the installation record with attacker-chosen commands. When vimball#RmVimball() later processes the matching record entry, the stored Ex commands, including operating-system commands invoked through :!, execute with the privileges of the user running Vim. This issue is fixed in version 9.2.0847.

Affected products

Remediation

Red Hat statement

This is an Important vulnerability in Vim where a crafted vimball can lead to arbitrary command execution. The flaw allows an attacker to embed malicious commands within a `.VimballRecord` file, which are then executed with user privileges during a later, unrelated vimball installation or removal. This extends the impact of processing untrusted vimball files beyond the initial installation.

Red Hat mitigation

Avoid installing or removing vimballs from untrusted sources. This vulnerability relies on a user processing a malicious vimball, which then injects commands that are executed during a subsequent vimball operation. Exercise caution when handling vimball files from unknown or unverified origins.

References (6)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner GitHub_M
Published Aug 11, 2026
Updated Aug 11, 2026
Reserved Aug 10, 2026
CISA Vulnrichment
Updated Aug 11, 2026
NVD
Status Awaiting Analysis
Modified Sep 9, 2026
Red Hat
Severity Important
Public date Aug 11, 2026
ENISA EUVD
Assigner n/a
Published n/a
Updated n/a
Exploited since n/a
Link n/a