CVE-2026-34714

Published
View on NVD ↗
CVSS v3
9.2
CRITICAL
CVSS v2
N/A
Affected
1
PROJECT

Description

Vim before 9.2.0272 allows code execution that happens immediately upon opening a crafted file in the default configuration, because %{expr} injection occurs with tabpanel lacking P_MLE.

The official Vim repository
GitHubGitHub
40.6K