CVE-2026-28417
published 2026-02-27CVE-2026-28417: Vim is an open source, command line text editor. Prior to version 9.2.0073, an OS command injection vulnerability exists in the `netrw` standard plugin bundled…
PriorityP351high7.8CVSS 3.1
AVLACLPRNUIRSUCHIHAH
EPSS
1.16%
63.7th percentile
Vim is an open source, command line text editor. Prior to version 9.2.0073, an OS command injection vulnerability exists in the `netrw` standard plugin bundled with Vim. By inducing a user to open a crafted URL (e.g., using the `scp://` protocol handler), an attacker can execute arbitrary shell commands with the privileges of the Vim process. Version 9.2.0073 fixes the issue.
Affected
12 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | vim | < vim 2:9.2.0119-1 (forky) | vim 2:9.2.0119-1 (forky) |
| msrc | azl3_vim_9.1.1616-1_on_azure_linux_3.0 | — | — |
| msrc | cbl2_vim_9.1.1616-1_on_cbl_mariner_2.0 | — | — |
| vim | vim | < 9.2.0073 | 9.2.0073 |
| vim | vim | >= 0 < 2:9.2.0119-1 | 2:9.2.0119-1 |
| vim | vim | >= 0 < 2:8.2.3995-1ubuntu2.26 | 2:8.2.3995-1ubuntu2.26 |
| vim | vim | >= 0 < 2:9.1.0016-1ubuntu7.10 | 2:9.1.0016-1ubuntu7.10 |
| vim | vim | >= 0 < 2:9.1.0967-1ubuntu6.1 | 2:9.1.0967-1ubuntu6.1 |
| vim | vim | >= 0 < 2:7.4.052-1ubuntu3.1+esm23 | 2:7.4.052-1ubuntu3.1+esm23 |
| vim | vim | >= 0 < 2:7.4.1689-3ubuntu1.5+esm29 | 2:7.4.1689-3ubuntu1.5+esm29 |
| vim | vim | >= 0 < 2:8.0.1453-1ubuntu1.13+esm14 | 2:8.0.1453-1ubuntu1.13+esm14 |
| vim | vim | >= 0 < 2:8.1.2269-1ubuntu5.32+esm2 | 2:8.1.2269-1ubuntu5.32+esm2 |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
osv7.8HIGH
vendor_ubuntu6.6MEDIUM
vendor_debian4.4MEDIUM
vendor_msrc4.4MEDIUM
vendor_redhat4.4MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Vim vulnerabilities
vendor_ubuntu·2026-03-16·CVSS 6.6
CVE-2026-25749 [MEDIUM] Vim vulnerabilities
Title: Vim vulnerabilities
Summary: Several security issues were fixed in Vim.
Rahul Hoysala discovered that Vim did not correctly handle certain tag
resolutions. An attacker could possibly use this issue to cause a denial
of service. (CVE-2026-25749)
It was discovered that Vim did not correctly handle processing certain
specialKey commands. An attacker could possibly use this issue to cause a
denial of service or execute arbitrary code. (CVE-2026-26269)
Kim Dong Han discovered that Vim did not correctly handle opening certain
URLs. If a user or system were tricked into opening a specially crafted
file, an attacker could possibly use this issue to execute arbitrary code.
(CVE-2026-28417)
Kim Dong Han discovered that Vim did not correctly handle parsing
Emacs-style tag files. An attack
Red Hat
vim: Vim: Arbitrary code execution via OS command injection in the netrw plugin
vendor_redhat·2026-02-27·CVSS 4.4
CVE-2026-28417 [MEDIUM] CWE-78 vim: Vim: Arbitrary code execution via OS command injection in the netrw plugin
vim: Vim: Arbitrary code execution via OS command injection in the netrw plugin
Vim is an open source, command line text editor. Prior to version 9.2.0073, an OS command injection vulnerability exists in the `netrw` standard plugin bundled with Vim. By inducing a user to open a crafted URL (e.g., using the `scp://` protocol handler), an attacker can execute arbitrary shell commands with the privileges of the Vim process. Version 9.2.0073 fixes the issue.
A flaw was found in Vim, an open-source command-line text editor. Specifically, an operating system (OS) command injection vulnerability exists in the `netrw` standard plugin. A remote attacker could exploit this by tricking a user into opening a specially crafted URL, such as one using the `scp://` protocol handler. Successful exploitat
Microsoft
Vim has OS Command Injection in netrw
vendor_msrc·2026-02-10·CVSS 4.4
CVE-2026-28417 [MEDIUM] CWE-86 Vim has OS Command Injection in netrw
Vim has OS Command Injection in netrw
Mariner: Mariner
GitHub_M: GitHub_M
Customer Action Required: Yes
Remediation: CBL-Mariner Releases
Reference: https://learn.microsoft.com/en-us/azure/azure-linux/tutorial-azure-linux-upgrade
Debian
CVE-2026-28417: vim - Vim is an open source, command line text editor. Prior to version 9.2.0073, an O...
vendor_debian·2026·CVSS 4.4
CVE-2026-28417 [MEDIUM] CVE-2026-28417: vim - Vim is an open source, command line text editor. Prior to version 9.2.0073, an O...
Vim is an open source, command line text editor. Prior to version 9.2.0073, an OS command injection vulnerability exists in the `netrw` standard plugin bundled with Vim. By inducing a user to open a crafted URL (e.g., using the `scp://` protocol handler), an attacker can execute arbitrary shell commands with the privileges of the Vim process. Version 9.2.0073 fixes the issue.
Scope: local
bookworm: open
bullseye: open
forky: resolved (fixed in 2:9.2.0119-1)
sid: resolved (fixed in 2:9.2.0119-1)
trixie: open
OSV
vim vulnerabilities
osv·2026-03-16·CVSS 6.6
CVE-2026-25749 [MEDIUM] vim vulnerabilities
vim vulnerabilities
Rahul Hoysala discovered that Vim did not correctly handle certain tag
resolutions. An attacker could possibly use this issue to cause a denial
of service. (CVE-2026-25749)
It was discovered that Vim did not correctly handle processing certain
specialKey commands. An attacker could possibly use this issue to cause a
denial of service or execute arbitrary code. (CVE-2026-26269)
Kim Dong Han discovered that Vim did not correctly handle opening certain
URLs. If a user or system were tricked into opening a specially crafted
file, an attacker could possibly use this issue to execute arbitrary code.
(CVE-2026-28417)
Kim Dong Han discovered that Vim did not correctly handle parsing
Emacs-style tag files. An attacker could possibly use this issue to cause
a denial of servic
OSV
CVE-2026-28417: Vim is an open source, command line text editor
osv·2026-02-27·CVSS 7.8
CVE-2026-28417 [HIGH] CVE-2026-28417: Vim is an open source, command line text editor
Vim is an open source, command line text editor. Prior to version 9.2.0073, an OS command injection vulnerability exists in the `netrw` standard plugin bundled with Vim. By inducing a user to open a crafted URL (e.g., using the `scp://` protocol handler), an attacker can execute arbitrary shell commands with the privileges of the Vim process. Version 9.2.0073 fixes the issue.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2026-28417 vim: Vim: Arbitrary code execution via OS command injection in the netrw plugin
bugzilla·2026-02-27·CVSS 4.4
CVE-2026-28417 [MEDIUM] CVE-2026-28417 vim: Vim: Arbitrary code execution via OS command injection in the netrw plugin
CVE-2026-28417 vim: Vim: Arbitrary code execution via OS command injection in the netrw plugin
Vim is an open source, command line text editor. Prior to version 9.2.0073, an OS command injection vulnerability exists in the `netrw` standard plugin bundled with Vim. By inducing a user to open a crafted URL (e.g., using the `scp://` protocol handler), an attacker can execute arbitrary shell commands with the privileges of the Vim process. Version 9.2.0073 fixes the issue.
Discussion:
This issue has been addressed in the following products:
Red Hat Enterprise Linux 10.0 Extended Update Support
Via RHSA-2026:6502 https://access.redhat.com/errata/RHSA-2026:6502
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 9.4 Extended Update Support
Via RHSA-2026
Wiz
CVE-2026-28417 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 4.4
CVE-2026-28417 [MEDIUM] CVE-2026-28417 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-28417 :
Vim vulnerability analysis and mitigation
netrw
scp://
Source : NVD
## 7.8
Score
Published February 27, 2026
Severity HIGH
CNA Score 4.4
Affected Technologies
Vim
Alma Linux
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 1.8
Exploitation Probability (EPSS) N/A
Affected packages and libraries
vim-X11
vim-common
Sources
Alpine 3.10, 3.11, 3.12, 3.13, 3.14, 3.15, 3.16, 3.17, 3.18, 3.19, 3.20, 3.21, 3.22 Severity HIGH Has Fix Added at: Mar 03, 2026
Alpine 3.23, edge Severity HIGH Has Fix Added at: Mar 02, 2026
CBL-Mariner 2.0 Severity MEDIUM Has Fix Added at: Mar 10, 2026
CBL-Mariner 3.0 Severity MEDIUM Has Fix Added at: Mar 13, 2026
Chainguard Has Fix Adde
2026-02-27
Published