Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Tue, 11 Aug 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 11 Aug 2026 15:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Vim is an open source, command line text editor. Prior to 9.2.0847, runtime/autoload/vimball.vim allows a crafted vimball member named .VimballRecord to overwrite the installation record with attacker-chosen commands. When vimball#RmVimball() later processes the matching record entry, the stored Ex commands, including operating-system commands invoked through :!, execute with the privileges of the user running Vim. This issue is fixed in version 9.2.0847. | |
| Title | Vim: Arbitrary Command Execution via Malicious `.VimballRecord` Entry Replay in `vimball.vim` | |
| Weaknesses | CWE-829 CWE-94 |
|
| References |
| |
| Metrics |
cvssV4_0
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-08-11T15:54:03.540Z
Reserved: 2026-08-10T19:37:41.444Z
Link: CVE-2026-73076
Updated: 2026-08-11T15:53:58.831Z
Status : Received
Published: 2026-08-11T16:17:38.980
Modified: 2026-08-11T16:17:38.980
Link: CVE-2026-73076
No data.
OpenCVE Enrichment
No data.