cbcvebase.
CVE-2026-34982
published 2026-04-06

CVE-2026-34982: Vim is an open source, command line text editor. Prior to version 9.2.0276, a modeline sandbox bypass in Vim allows arbitrary OS command execution when a user…

PriorityP347high8.2CVSS 3.1
AVLACLPRNUIRSCCHIHAN
EPSS
0.47%
37.6th percentile
Vim is an open source, command line text editor. Prior to version 9.2.0276, a modeline sandbox bypass in Vim allows arbitrary OS command execution when a user opens a crafted file. The `complete`, `guitabtooltip` and `printheader` options are missing the `P_MLE` flag, allowing a modeline to be executed. Additionally, the `mapset()` function lacks a `check_secure()` call, allowing it to be abused from sandboxed expressions. Commit 9.2.0276 fixes the issue.

Affected

4 ranges
VendorProductVersion rangeFixed in
debianvim< vim 2:9.2.0315-1 (sid)vim 2:9.2.0315-1 (sid)
msrcazl3_vim_9.2.0240-1_on_azure_linux_3.0
msrccbl2_vim_9.2.0240-1_on_cbl_mariner_2.0
vimvim< 9.2.02769.2.0276

CVSS provenance

nvdv3.18.2HIGHCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N
osv8.2HIGH
vendor_debian8.2HIGH
vendor_msrc8.2HIGH
vendor_redhat8.2HIGH
vendor_ubuntu5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.