CVE-2026-28417 | Teknoloji dünyasından en güncel haberleri ve güvenlikle ilgili gelişmeleri takip edin.

Vim is an open source, command line text editor. Prior to version 9.2.0073, an OS command injection vulnerability exists in the `netrw` standard plugin bundled…
Medium CVSS: 4.4

CVE-2026-28417

Vim is an open source, command line text editor. Prior to version 9.2.0073, an OS command injection vulnerability exists in the `netrw` standard plugin bundled with Vim. By inducing a user to open a crafted URL (e.g., using the `scp://` protocol handler), an attacker can execute arbitrary shell commands with the privileges of the Vim process. Version 9.2.0073 fixes the issue.
Vendor
Vim
Product
Vim
CWE
CWE-86
Yayın Tarihi
2026-02-27 22:16:24
Güncelleme
2026-03-03 17:50:29
Source Identifier
security-advisories@github.com
KEV Date Added
-

Kategoriler

Referanslar