Vim: Arbitrary Code Execution via Shell Keyword Lookup
Published Aug 11, 2026
8.4
HIGHCVSS 4.0
EPSS 0.14%
Description
Vim is an open source, command line text editor. Prior to 9.2.0839, the runtime/ftplugin/sh.vim, runtime/ftplugin/zsh.vim, and runtime/ftplugin/ps1.vim filetype plugins pass attacker-controlled Visual-mode selections from K through keywordprg commands without safely separating shell arguments. fnameescape() and PATH_ESC_CHARS do not neutralize shell metacharacters before ShKeywordPrg, ZshKeywordPrg, or GetHelp invokes bash, zsh, or PowerShell, allowing arbitrary operating-system commands to execute with the privileges of the user running Vim. This issue is fixed in version 9.2.0839.
Affected products
-
- Version < 9.2.0839StatusaffectedConstraints-
- Version
No data.
Red Hat Enterprise Linux 10
vim-2:9.1.083-9.el10_2.20
Fixed · RHSA-2026:66336
Red Hat Enterprise Linux 9
vim-2:8.2.2637-26.el9_8.21
Fixed · RHSA-2026:66366
Red Hat Enterprise Linux 9
vim-2:8.2.2637-26.el9_8.21
Fixed · RHSA-2026:66366
Red Hat Update Infrastructure 5
rhui5/cds-kubernetes-rhel9:1789479916
Fixed · RHSA-2026:67956
Red Hat Update Infrastructure 5
rhui5/cds-rhel9:1789479900
Fixed · RHSA-2026:67956
Red Hat Update Infrastructure 5
rhui5/haproxy-rhel9:1789479891
Fixed · RHSA-2026:67956
Red Hat Update Infrastructure 5
rhui5/installer-rhel9:1789482961
Fixed · RHSA-2026:67956
Red Hat Enterprise Linux 6
vim
Not affected
Red Hat Enterprise Linux 7
vim
Not affected
Red Hat Enterprise Linux 8
vim
Not affected
Red Hat Hardened Images
vim
Not affected
Red Hat OpenShift Container Platform 4
openshift/ose-rhel-coreos-8
Not affected
Red Hat OpenShift Container Platform 4
openshift/ose-rhel-coreos-9
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 10 | vim-2:9.1.083-9.el10_2.20 | Fixed | RHSA-2026:66336 |
| Red Hat Enterprise Linux 9 | vim-2:8.2.2637-26.el9_8.21 | Fixed | RHSA-2026:66366 |
| Red Hat Enterprise Linux 9 | vim-2:8.2.2637-26.el9_8.21 | Fixed | RHSA-2026:66366 |
| Red Hat Update Infrastructure 5 | rhui5/cds-kubernetes-rhel9:1789479916 | Fixed | RHSA-2026:67956 |
| Red Hat Update Infrastructure 5 | rhui5/cds-rhel9:1789479900 | Fixed | RHSA-2026:67956 |
| Red Hat Update Infrastructure 5 | rhui5/haproxy-rhel9:1789479891 | Fixed | RHSA-2026:67956 |
| Red Hat Update Infrastructure 5 | rhui5/installer-rhel9:1789482961 | Fixed | RHSA-2026:67956 |
| Red Hat Enterprise Linux 6 | vim | Not affected | n/a |
| Red Hat Enterprise Linux 7 | vim | Not affected | n/a |
| Red Hat Enterprise Linux 8 | vim | Not affected | n/a |
| Red Hat Hardened Images | vim | Not affected | n/a |
| Red Hat OpenShift Container Platform 4 | openshift/ose-rhel-coreos-8 | Not affected | n/a |
| Red Hat OpenShift Container Platform 4 | openshift/ose-rhel-coreos-9 | Not affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
This Important vulnerability in Vim's shell plugins allows full system compromise in Red Hat environments if a user selects crafted text in Visual mode and triggers a keyword lookup. This does not affect RHEL 8 and older versions.
Red Hat mitigation
To mitigate this vulnerability, users can disable the `keywordprg` option for shell script filetypes. This prevents Vim from executing external commands via the `K` command with potentially untrusted input. Create or edit the following files in your Vim configuration directory: - `~/.vim/after/ftplugin/sh.vim`: `setlocal keywordprg=` - `~/.vim/after/ftplugin/zsh.vim`: `setlocal keywordprg=` - `~/.vim/after/ftplugin/ps1.vim`: `setlocal keywordprg=` This change takes effect the next time a shell script is opened in Vim.
References (7)
- https://access.redhat.com/security/cve/CVE-2026-73077 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2514065 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-56233 Advisory
- https://github.com/vim/vim/commit/c5a82fe013e73c98004ad7cd4f906b1ad1ed610e x_refsource_MISC
- https://github.com/vim/vim/security/advisories/GHSA-r5v6-q6j8-8qw2 x_refsource_CONFIRM
- https://nvd.nist.gov/vuln/detail/CVE-2026-73077
- https://www.cve.org/CVERecord?id=CVE-2026-73077
Change history (0)
No recorded changes yet.