CVE-2026-39881

Severity CVSS v4.0:
Pending analysis
Type:
CWE-94 Code Injection
Publication date:
08/04/2026
Last modified:
08/04/2026

Description

Vim is an open source, command line text editor. Prior to 9.2.0316, a command injection vulnerability in Vim's netbeans interface allows a malicious netbeans server to execute arbitrary Ex commands when Vim connects to it, via unsanitized strings in the defineAnnoType and specialKeys protocol messages. This vulnerability is fixed in 9.2.0316.