LOWVulnerability
CVE-2026-73078
Vim is an open source, command line text editor. Prior to 9.2.0840, runtime/plugin/netrwPlugin.vim loads netrw and runtime/pack/dist/opt/netrw/autoload/netrw.vim constructs Bookmarks, History, and Targets menu entries by interpolating attacker-controlled directory paths into executed :menu commands. s:NetrwBookmarkMenu(), s:NetrwTgtMenu(), g:netrw_menu_escape, EX_TRLBAR, and netrw#MakeTgt() fail to neutralize the | command separator or single quotes at five construction sites, allowing a crafted path browsed or bookmarked in GUI Vim to execute arbitrary Ex and operating-system commands. This issue is fixed in version 9.2.0840.
Properties
- epss_score
- 0.00336
- cve_id
- CVE-2026-73078
- published_at
- 2026-08-11T16:17:39.573
- last_modified
- 2026-09-09T20:44:04.357
- epss_percentile
- 0.26598
Related Entities (4)
ENRICHED_BY (1)
→[Source]FIRST EPSS
HAS_WEAKNESS (2)
→[Weakness]Improper Neutralization of Special Elements used in a Command ('Command Injection')
→[Weakness]Incomplete List of Disallowed Inputs
DESCRIBED_BY (1)
→[Source]NVD
Explore deeper with Ninja Signal's threat intelligence graph