Back

HIGH

Vim: Arbitrary Code Execution via Shell Keyword Lookup

Published Aug 11, 2026

Description

Vim is an open source, command line text editor. Prior to 9.2.0839, the runtime/ftplugin/sh.vim, runtime/ftplugin/zsh.vim, and runtime/ftplugin/ps1.vim filetype plugins pass attacker-controlled Visual-mode selections from K through keywordprg commands without safely separating shell arguments. fnameescape() and PATH_ESC_CHARS do not neutralize shell metacharacters before ShKeywordPrg, ZshKeywordPrg, or GetHelp invokes bash, zsh, or PowerShell, allowing arbitrary operating-system commands to execute with the privileges of the user running Vim. This issue is fixed in version 9.2.0839.

Affected products

Remediation

Red Hat statement

This Important vulnerability in Vim's shell plugins allows full system compromise in Red Hat environments if a user selects crafted text in Visual mode and triggers a keyword lookup. This does not affect RHEL 8 and older versions.

Red Hat mitigation

To mitigate this vulnerability, users can disable the `keywordprg` option for shell script filetypes. This prevents Vim from executing external commands via the `K` command with potentially untrusted input. Create or edit the following files in your Vim configuration directory: - `~/.vim/after/ftplugin/sh.vim`: `setlocal keywordprg=` - `~/.vim/after/ftplugin/zsh.vim`: `setlocal keywordprg=` - `~/.vim/after/ftplugin/ps1.vim`: `setlocal keywordprg=` This change takes effect the next time a shell script is opened in Vim.

References (7)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner GitHub_M
Published Aug 11, 2026
Updated Aug 11, 2026
Reserved Aug 10, 2026
CISA Vulnrichment
Updated Aug 11, 2026
NVD
Status Analyzed
Modified Oct 6, 2026
Red Hat
Severity Important
Public date Aug 11, 2026
ENISA EUVD
Assigner GitHub_M
Published Aug 11, 2026
Updated Aug 11, 2026
Exploited since n/a
EUVD-2026-56233