CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

CVE-2026-73078

unknowncovered by 2 sourcesfirst seen 2026-08-11
Vim is an open source, command line text editor. Prior to 9.2.0840, runtime/plugin/netrwPlugin.vim loads netrw and runtime/pack/dist/opt/netrw/autoload/netrw.vim constructs Bookmarks, History, and Targets menu entries by interpolating attacker-controlled directory paths into executed :menu commands. s:NetrwBookmarkMenu(), s:NetrwTgtMenu(), g:netrw_menu_escape, EX_TRLBAR, and netrw#MakeTgt() fail to neutralize the | command separator or single quotes at five construction sites, allowing a crafted path browsed or bookmarked in GUI Vim to execute arbitrary Ex and operating-system commands. This issue is fixed in version 9.2.0840.

CSIRTS triage

What
Arbitrary code execution through Netrw menu construction.
Who is affected
Vim users with Netrw functionality enabled are affected.
Urgency
Severity unknown; monitor for exploitation and user reports before prioritizing.
Action
Monitor Vim security announcements and apply patch when released.

AI-assisted analysis generated from the source advisory — verify against the original.

⚡ Watch CVE-2026-73078

Get an email if CVE-2026-73078 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.

Exploitation outlook

Advisory coverage (2)

External references

NVD record for CVE-2026-73078

CVE.org record

Embed the live status

CVE-2026-73078 live status badge — this badge updates automatically when the KEV or exploit status changes. How to embed it →

[![CVE-2026-73078 status](https://www.csirts.com/badge/CVE-2026-73078)](https://www.csirts.com/cve/CVE-2026-73078)