Description
Vim is an open source, command line text editor. Prior to version 9.2.0276, a modeline sandbox bypass in Vim allows arbitrary OS command execution when a user opens a crafted file. The `complete`, `guitabtooltip` and `printheader` options are missing the `P_MLE` flag, allowing a modeline to be executed. Additionally, the `mapset()` function lacks a `check_secure()` call, allowing it to be abused from sandboxed expressions. Commit 9.2.0276 fixes the issue.
Published: 2026-04-06
Score: 8.2 High
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Analysis and contextual insights are available on OpenCVE Cloud.

Remediation

No vendor fix or workaround currently provided.

Additional remediation guidance may be available on OpenCVE Cloud.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Ubuntu USN Ubuntu USN USN-8171-1 Vim vulnerabilities
References
Link Providers
http://www.openwall.com/lists/oss-security/2026/04/01/1 cve-icon cve-icon
https://access.redhat.com/errata/RHSA-2026:11389 cve-icon
https://access.redhat.com/errata/RHSA-2026:11509 cve-icon
https://access.redhat.com/errata/RHSA-2026:11510 cve-icon
https://access.redhat.com/errata/RHSA-2026:19073 cve-icon
https://access.redhat.com/errata/RHSA-2026:19224 cve-icon
https://access.redhat.com/errata/RHSA-2026:21275 cve-icon
https://access.redhat.com/errata/RHSA-2026:22634 cve-icon
https://access.redhat.com/errata/RHSA-2026:28049 cve-icon
https://access.redhat.com/errata/RHSA-2026:28050 cve-icon
https://access.redhat.com/errata/RHSA-2026:28133 cve-icon
https://access.redhat.com/errata/RHSA-2026:30078 cve-icon
https://access.redhat.com/errata/RHSA-2026:30087 cve-icon
https://access.redhat.com/errata/RHSA-2026:30088 cve-icon
https://access.redhat.com/errata/RHSA-2026:30089 cve-icon
https://access.redhat.com/errata/RHSA-2026:30900 cve-icon
https://access.redhat.com/errata/RHSA-2026:33453 cve-icon
https://access.redhat.com/errata/RHSA-2026:34476 cve-icon
https://access.redhat.com/errata/RHSA-2026:34477 cve-icon
https://access.redhat.com/errata/RHSA-2026:36004 cve-icon
https://access.redhat.com/errata/RHSA-2026:36005 cve-icon
https://access.redhat.com/errata/RHSA-2026:36006 cve-icon
https://access.redhat.com/security/cve/CVE-2026-34982 cve-icon
https://bugzilla.redhat.com/show_bug.cgi?id=2455400 cve-icon
https://github.com/vim/vim/commit/75661a66a1db1e1f3f1245c615 cve-icon cve-icon cve-icon
https://github.com/vim/vim/releases/tag/v9.2.0276 cve-icon cve-icon cve-icon
https://github.com/vim/vim/security/advisories/GHSA-8h6p-m6gr-mpw9 cve-icon cve-icon cve-icon
https://nvd.nist.gov/vuln/detail/CVE-2026-34982 cve-icon
https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-34982.json cve-icon
https://www.cve.org/CVERecord?id=CVE-2026-34982 cve-icon
History

Wed, 22 Apr 2026 20:15:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:vim:vim:*:*:*:*:*:*:*:*

Tue, 07 Apr 2026 00:00:00 +0000

Type Values Removed Values Added
First Time appeared Vim
Vim vim
Vendors & Products Vim
Vim vim
References
Metrics threat_severity

None

threat_severity

Important


Mon, 06 Apr 2026 16:45:00 +0000

Type Values Removed Values Added
References
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 06 Apr 2026 15:30:00 +0000

Type Values Removed Values Added
Description Vim is an open source, command line text editor. Prior to version 9.2.0276, a modeline sandbox bypass in Vim allows arbitrary OS command execution when a user opens a crafted file. The `complete`, `guitabtooltip` and `printheader` options are missing the `P_MLE` flag, allowing a modeline to be executed. Additionally, the `mapset()` function lacks a `check_secure()` call, allowing it to be abused from sandboxed expressions. Commit 9.2.0276 fixes the issue.
Title Vim modeline bypass via various options affects Vim < 9.2.0276
Weaknesses CWE-78
References
Metrics cvssV3_1

{'score': 8.2, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-07-15T01:03:29.473Z

Reserved: 2026-03-31T19:38:31.617Z

Link: CVE-2026-34982

cve-icon Vulnrichment

Updated: 2026-04-06T15:19:17.901Z

cve-icon NVD

Status : Modified

Published: 2026-04-06T16:16:38.777

Modified: 2026-07-15T02:20:36.983

Link: CVE-2026-34982

cve-icon Redhat

Severity : Important

Publid Date: 2026-04-06T15:16:48Z

Links: CVE-2026-34982 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-04-06T21:32:23Z

Weaknesses