CVE-2026-34714OS Command Injection in VIM

Severity
8.6HIGHNVD
EPSS
0.0%
top 92.53%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedMar 30
Latest updateApr 6

Description

Vim before 9.2.0272 allows code execution that happens immediately upon opening a crafted file in the default configuration, because %{expr} injection occurs with tabpanel lacking P_MLE.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:HExploitability: 1.8 | Impact: 6.0

Affected Packages2 packages

NVDvim/vim< 9.2.0272
debiandebian/vim< vim 2:9.2.0315-1 (sid)

Patches

🔴Vulnerability Details

3
OSV
CVE-2026-34714: (Vim before 92026-03-31
OSV
CVE-2026-34714: Vim before 92026-03-30
GHSA
GHSA-mfxw-q267-mgp6: Vim before 92026-03-30

📋Vendor Advisories

2
Red Hat
vim: Vim: Arbitrary code execution via crafted file2026-03-30
Debian
CVE-2026-34714: vim - Vim before 9.2.0272 allows code execution that happens immediately upon opening ...2026

🕵️Threat Intelligence

15
Hackernews
⚡ Weekly Recap: Axios Hack, Chrome 0-Day, Fortinet Exploits, Paragon Spyware and More2026-04-06
Wiz
CVE-2026-34714 Impact, Exploitability, and Mitigation Steps | Wiz
Wiz
CVE-2026-28422 Impact, Exploitability, and Mitigation Steps | Wiz
Wiz
CVE-2026-28419 Impact, Exploitability, and Mitigation Steps | Wiz
Wiz
CVE-2026-25749 Impact, Exploitability, and Mitigation Steps | Wiz

💬Community

1
Bugzilla
CVE-2026-34714 vim: Vim: Arbitrary code execution via crafted file [fedora-all]2026-03-30
CVE-2026-34714 — OS Command Injection in VIM | cvebase