CVE-2026-39881

CVE-2026-39881CVE-2026-39881

vim / vim

Description

Vim is an open source, command line text editor. Prior to 9.2.0316, a command injection vulnerability in Vim's netbeans interface allows a malicious netbeans server to execute arbitrary Ex commands when Vim connects to it, via unsanitized strings in the defineAnnoType and specialKeys protocol messages. This vulnerability is fixed in 9.2.0316.

Scoring

CVSS 5.0 ()
VectorCVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:L/I:H/A:N
Last modified2026-07-24
Sourced from NVD. Curated for EU compliance use cases by Adam Lundqvist, Founder at SQUR.