oss-sec mailing list archives From : Christian Brabandt <cb () 256bit org> Date : Tue, 31 Mar 2026 20:37:06 +0200 Vim modeline bypass via various options affects Vim < 9.2.0276 ============================================================== Date: 31.03.2026 Severity: High CVE: *not yet assigned* CWE: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') (CWE-78) ## Summary A modeline sandbox bypass in Vim allows arbitrary OS command execution when a u