CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

CVE-2026-73077

unknowncovered by 2 sourcesfirst seen 2026-08-11
Vim is an open source, command line text editor. Prior to 9.2.0839, the runtime/ftplugin/sh.vim, runtime/ftplugin/zsh.vim, and runtime/ftplugin/ps1.vim filetype plugins pass attacker-controlled Visual-mode selections from K through keywordprg commands without safely separating shell arguments. fnameescape() and PATH_ESC_CHARS do not neutralize shell metacharacters before ShKeywordPrg, ZshKeywordPrg, or GetHelp invokes bash, zsh, or PowerShell, allowing arbitrary operating-system commands to execute with the privileges of the user running Vim. This issue is fixed in version 9.2.0839.

CSIRTS triage

What
Arbitrary code can be executed in Vim through shell keyword lookup functionality.
Who is affected
Vim users in environments where shell keyword resolution is enabled and attackers can influence input files.
Urgency
Unknown severity; immediate assessment needed to determine code execution feasibility.
Action
Apply Vim security updates and disable shell keyword lookup if not required.

AI-assisted analysis generated from the source advisory — verify against the original.

⚡ Watch CVE-2026-73077

Get an email if CVE-2026-73077 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.

Exploitation outlook

Advisory coverage (2)

External references

NVD record for CVE-2026-73077

CVE.org record

Embed the live status

CVE-2026-73077 live status badge — this badge updates automatically when the KEV or exploit status changes. How to embed it →

[![CVE-2026-73077 status](https://www.csirts.com/badge/CVE-2026-73077)](https://www.csirts.com/cve/CVE-2026-73077)