Vulnerability Description
Vim is an open source, command line text editor. Prior to 9.2.0663, a Vimscript code injection vulnerability exists in s:NetrwLocalRmFile() in the netrw plugin (runtime/pack/dist/opt/netrw/autoload/netrw.vim) when deleting a local file from the browser. A filename derived from the buffer's directory listing is interpolated into an Ex command line passed to :execute with only the backslash character escaped, allowing a crafted filename containing a bar (|) to terminate the intended command and execute arbitrary Vimscript, including shell commands via :call system() and :!. This vulnerability is fixed in 9.2.0663.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Vim | Vim | < 9.2.0663 |
Related Weaknesses (CWE)
References
- https://github.com/vim/vim/commit/55bc757a5d436e59d50fe43f7cda94b118f86cb2Patch
- https://github.com/vim/vim/releases/tag/v9.2.0663Product
- https://github.com/vim/vim/security/advisories/GHSA-vhh8-v6wx-hjjhVendor Advisory
FAQ
What is CVE-2026-55895?
CVE-2026-55895 is a vulnerability with a CVSS score of 7.8 (HIGH). Vim is an open source, command line text editor. Prior to 9.2.0663, a Vimscript code injection vulnerability exists in s:NetrwLocalRmFile() in the netrw plugin (runtime/pack/dist/opt/netrw/autoload/ne...
How severe is CVE-2026-55895?
CVE-2026-55895 has been rated HIGH with a CVSS base score of 7.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-55895?
Check the references section above for vendor advisories and patch information. Affected products include: Vim Vim.