Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
2681 articles · 111168 vulns · 38/41 feeds (7d)
← Back to list
EST
PRE-CVEPATCHED
vim

Command injection via backtick expansion in tag filenames in Vim

56% confidence

Description

A command injection vulnerability exists in Vim's tag file processing. When resolving a tag, the filename field from the tags file is passed through wildcard expansion to resolve environment variables and wildcards. If the filename field contains backtick syntax, Vim executes the embedded command via the system shell with the full privileges of the running user.

Affected Products

VendorProductVersions
vim—< 9.2.0357

Related News (1 articles)

Tier C
oss-security5h ago
[vim-security] Command injection via backtick expansion in tag filenames in Vim < v9.2.0357
→ No new info (linked only)
CISA KEV❌ No
Actively exploited❌ No
Patch available
9.2.0357
CWECWE-78
PublishedApr 15, 2026
Last enriched5h ago
Trending Score23
Source articles1
Independent1
Info Completeness6/14
Missing: cve_id, product, cvss, epss, kev, exploit, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

HIGHCVE-2026-34982
Vim modeline bypass via various options affects Vim < 9.2.0276
Trending: 20
MEDIUMCVE-2026-39881
Vim Ex command injection in Vims NetBeans integration
Trending: 20
MEDIUMCVE-2026-32249
Vim is an open source, command line text editor. From 9.1.0011 to before 9.2.0137, Vim's NFA regex compiler, when encountering a collection containing a combining character as the endpoint of a charac
Trending: 20
CRITICALCVE-2026-35177EXP
Path traversal issue with zip.vim in Vim
Trending: 18
MEDIUMCVE-2026-33412
Vim is an open source, command line text editor. Prior to version 9.2.0202, a command injection vulnerability exists in Vim's glob() function on Unix-like systems. By including a newline character (\n
Trending: 13

Pin to Dashboard

Verification

State: reported
Confidence: 56%

Vulnerability Timeline

CVE Published
Apr 15, 2026
Patch Available
Apr 15, 2026
Discovered by ZDM
Apr 15, 2026