Red HatCVE-2026-43961
Red Hat Vim: code injection
High7.8CVE-2026-43961 · Published Aug 19, 2026 · updated Sep 22, 2026
A flaw was found in Vim's netrw plugin. A crafted filename containing quote characters and expression fragments can break out of the quoted context during mark/unmark operations, allowing arbitrary Vimscript execution. This can be leveraged to run shell commands with the privileges of the user running Vim.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| Red Hat Enterprise Linux 10 Product | all versions | No fix yet |
| Red Hat Enterprise Linux 6 Product | all versions | No fix yet |
| Red Hat Enterprise Linux 7 Product | all versions | No fix yet |
| Red Hat Enterprise Linux 8 Product | all versions | No fix yet |
| Red Hat Enterprise Linux 9 Product | all versions | No fix yet |
| Red Hat OpenShift Container Platform 4 Product | all versions | No fix yet |
| all versions | No fix yet | |
| vim Product | < 9.2.0480 | 9.2.0480 |
Details and references
- CVSS 3.1
- CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
- Severity from
- the vendor (its own CVE record or advisory)
- Weakness
- CWE-94
- www.cve.org/CVERecord?id=CVE-2026-43961
- nvd.nist.gov/vuln/detail/CVE-2026-43961
- access.redhat.com/errata/RHSA-2026:57614
- access.redhat.com/security/cve/CVE-2026-43961
- bugzilla.redhat.com/show_bug.cgi?id=2460434
- github.com/vim/vim/security/advisories/GHSA-66hr-7p6x-x5j3
- www.openwall.com/lists/oss-security/2026/05/14/7
More Red Hat advisories
All Red Hat| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Aug 19 | Red Hat search-indexer. This vulnerability: protection mechanism failure | Medium6.8 | No fix yet |
| Aug 19 | Red Hat acm-operator-bundle. The build process: untrusted functionality included | High8.0 | No fix yet |
| Aug 19 | Red Hat mce-operator-bundle. The build process fetches: remote code execution | High7.7 | No fix yet |
| Aug 19 | Red Hat Advanced Cluster Management for Kubernetes 2: improper access control | Critical9.9 | No fix yet |
| Aug 19 | Red Hat: authentication bypass | Critical9.3 | No fix yet |
| Aug 19 | Red Hat volsync-addon-controller. This vulnerability: code injection | Medium6.2 | No fix yet |