Command Injection Affecting vim/vim package, versions [,9.2.0357)


Severity

Recommended
0.0
medium
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.5% (39th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-UNMANAGED-VIMVIM-16321062
  • published29 Apr 2026
  • disclosed24 Apr 2026
  • creditsrixivas, andynx90

Introduced: 24 Apr 2026

CVE-2026-41411  (opens in a new tab)
CWE-78  (opens in a new tab)

How to fix?

Upgrade vim/vim to version 9.2.0357 or higher.

Overview

Affected versions of this package are vulnerable to Command Injection in the tag file processing process. An attacker can execute arbitrary commands with the privileges of the running user by crafting a malicious tag file containing backtick syntax in the filename field, which is then executed by the system shell when resolving a tag.

Workaround

This vulnerability can be mitigated by exercising caution when opening or processing tag files from untrusted sources. Users should avoid loading tag files from unknown or suspicious origins to prevent the execution of arbitrary commands.

CVSS Base Scores

version 4.0
version 3.1