Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNews
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
831 articles · 101718 vulns · 38/41 feeds (7d)
← Back to list
EST
PRE-CVE
vim

Vim tabpanel modeline escape

56% confidence

Description

A vulnerability in Vim allows for modeline escape in versions prior to 9.2.0272. [Auto-archived: reprocess_no_remaining_articles — 2026-04-01T21:35:21.734Z]

Affected Products

VendorProductVersions
vim—< 9.2.0272

Related News (3 articles)

Tier C
oss-security15h ago
Re: [vim-security] Vim tabpanel modeline escape affects Vim < 9.2.0272
→ No new info (linked only)
Tier C
oss-security1d ago
Re: [vim-security] Vim tabpanel modeline escape affects Vim < 9.2.0272
→ No new info (linked only)
Tier C
oss-security1d ago
Re: [vim-security] Vim tabpanel modeline escape affects Vim < 9.2.0272
→ No new info (linked only)
CISA KEV❌ No
Actively exploited❌ No
PublishedApr 1, 2026
Last enriched2h ago
Trending Score21
Source articles3
Independent1
Info Completeness4/14
Missing: cve_id, product, cvss, epss, cwe, kev, exploit, patch, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

CRITICALCVE-2026-34714
Vim before 9.2.0272 allows code execution that happens immediately upon opening a crafted file in the default configuration, because %{expr} injection occurs with tabpanel lacking P_MLE.
Trending: 45
MEDIUMCVE-2026-25749
Vim is an open source, command line text editor. Prior to version 9.1.2132, a heap buffer overflow vulnerability exists in Vim's tag file resolution logic when processing the 'helpfile' option. The vu
Trending: 22
MEDIUMCVE-2026-33412
Vim is an open source, command line text editor. Prior to version 9.2.0202, a command injection vulnerability exists in Vim's glob() function on Unix-like systems. By including a newline character (\n
Trending: 18
MEDIUMCVE-2026-28419
Vim is an open source, command line text editor. Prior to version 9.2.0075, a heap-based buffer underflow exists in Vim's Emacs-style tags file parsing logic. When processing a malformed tags file whe
Trending: 15
MEDIUMCVE-2026-28417
Vim is an open source, command line text editor. Prior to version 9.2.0073, an OS command injection vulnerability exists in the `netrw` standard plugin bundled with Vim. By inducing a user to open a c
Trending: 15

Pin to Dashboard

Verification

State: archived
Confidence: 56%

Vulnerability Timeline

CVE Published
Apr 1, 2026
Discovered by ZDM
Apr 1, 2026