LOWVulnerability
CVE-2026-73076
Vim is an open source, command line text editor. Prior to 9.2.0847, runtime/autoload/vimball.vim allows a crafted vimball member named .VimballRecord to overwrite the installation record with attacker-chosen commands. When vimball#RmVimball() later processes the matching record entry, the stored Ex commands, including operating-system commands invoked through :!, execute with the privileges of the user running Vim. This issue is fixed in version 9.2.0847.
Properties
- epss_score
- 0.00131
- cve_id
- CVE-2026-73076
- published_at
- 2026-08-11T16:17:38.980
- last_modified
- 2026-09-09T20:44:04.357
- epss_percentile
- 0.03028
Related Entities (4)
ENRICHED_BY (1)
→[Source]FIRST EPSS
HAS_WEAKNESS (2)
→[Weakness]Improper Control of Generation of Code ('Code Injection')
→[Weakness]Inclusion of Functionality from Untrusted Control Sphere
DESCRIBED_BY (1)
→[Source]NVD
Explore deeper with Ninja Signal's threat intelligence graph