{"cvss":7.3,"datePublished":"2026-06-11T19:16:44.160","dateUpdated":"2026-09-18T13:18:28.190","description":"Vim is an open source, command line text editor. Prior to version 9.2.0495, a Vimscript code injection vulnerability exists in s:NetrwBookHistSave() in the netrw plugin (runtime/pack/dist/opt/netrw/autoload/netrw.vim) when serializing browsed directory paths to the history file ~/.vim/.netrwhist. A directory name derived from the filesystem is interpolated into a single-quoted Vimscript string literal without escaping embedded single quotes, allowing a crafted directory name to break out of the string context and execute arbitrary Vimscript, including shell commands via system() and :!, the next time the history file is sourced. This issue has been patched in version 9.2.0495.","id":"CVE-2026-47162","raw":{"affected":[{"affectedData":[{"product":"vim","vendor":"vim","versions":[{"status":"affected","version":"< 9.2.0495"}]}],"source":"security-advisories@github.com"},{"affectedData":[{"collectionURL":"https://access.redhat.com/downloads/content/package-browser/","cpes":["cpe:/o:redhat:enterprise_linux:10.2"],"defaultStatus":"affected","packageName":"vim","product":"Red Hat Enterprise Linux 10","vendor":"Red Hat","versions":[{"lessThan":"*","status":"unaffected","version":"2:9.1.083-9.el10_2.7","versionType":"rpm"}]},{"collectionURL":"https://access.redhat.com/downloads/content/package-browser/","cpes":["cpe:/o:redhat:enterprise_linux_eus:10.0"],"defaultStatus":"affected","packageName":"vim","product":"Red Hat Enterprise Linux 10.0 Extended Update Support","vendor":"Red Hat","versions":[{"lessThan":"*","status":"unaffected","version":"2:9.1.083-5.el10_0.4","versionType":"rpm"}]},{"collectionURL":"https://access.redhat.com/downloads/content/package-browser/","cpes":["cpe:/o:redhat:rhel_els:7"],"defaultStatus":"affected","packageName":"vim","product":"Red Hat Enterprise Linux 7 Extended Lifecycle Support","vendor":"Red Hat","versions":[{"lessThan":"*","status":"unaffected","version":"2:7.4.629-8.el7_9.2","versionType":"rpm"}]},{"collectionURL":"https://access.redhat.com/downloads/content/package-browser/","cpes":["cpe:/a:redhat:enterprise_linux:8","cpe:/o:redhat:enterprise_linux:8"],"defaultStatus":"affected","packageName":"vim","product":"Red Hat Enterprise Linux 8","vendor":"Red Hat","versions":[{"lessThan":"*","status":"unaffected","version":"2:8.0.1763-27.el8_10","versionType":"rpm"}]},{"collectionURL":"https://access.redhat.com/downloads/content/package-browser/","cpes":["cpe:/a:redhat:enterprise_linux:9","cpe:/o:redhat:enterprise_linux:9"],"defaultStatus":"affected","packageName":"vim","product":"Red Hat Enterprise Linux 9","vendor":"Red Hat","versions":[{"lessThan":"*","status":"unaffected","version":"2:8.2.2637-26.el9_8.10","versionType":"rpm"}]},{"collectionURL":"https://access.redhat.com/downloads/content/package-browser/","cpes":["cpe:/a:redhat:openshift:4.22::el9"],"defaultStatus":"affected","packageName":"rhcos","product":"Red Hat OpenShift Container Platform 4.22","vendor":"Red Hat","versions":[{"lessThan":"*","status":"unaffected","version":"4.22.9.8.202608130832-0","versionType":"rpm"}]},{"collectionURL":"https://catalog.redhat.com/software/containers/","cpes":["cpe:/a:redhat:insights_proxy:1.5::el9"],"defaultStatus":"affected","packageName":"insights-proxy/insights-proxy-container-rhel9","product":"Red Hat Insights proxy 1.5","vendor":"Red Hat","versions":[{"lessThan":"*","status":"unaffected","version":"1786433656","versionType":"rpm"}]},{"collectionURL":"https://catalog.redhat.com/software/containers/","cpes":["cpe:/a:redhat:rhui:5::el9"],"defaultStatus":"affected","packageName":"rhui5/cds-kubernetes-tp-rhel9","product":"Red Hat Update Infrastructure 5","vendor":"Red Hat","versions":[{"lessThan":"*","status":"unaffected","version":"1787241211","versionType":"rpm"}]},{"collectionURL":"https://catalog.redhat.com/software/containers/","cpes":["cpe:/a:redhat:rhui:5::el9"],"defaultStatus":"affected","packageName":"rhui5/installer-tp-rhel9","product":"Red Hat Update Infrastructure 5","vendor":"Red Hat","versions":[{"lessThan":"*","status":"unaffected","version":"1787135742","versionType":"rpm"}]},{"collectionURL":"https://catalog.redhat.com/software/containers/","cpes":["cpe:/a:redhat:rhui:5::el9"],"defaultStatus":"affected","packageName":"rhui5/rhua-tp-rhel9","product":"Red Hat Update Infrastructure 5","vendor":"Red Hat","versions":[{"lessThan":"*","status":"unaffected","version":"1787241260","versionType":"rpm"}]},{"collectionURL":"https://access.redhat.com/downloads/content/package-browser/","cpes":["cpe:/o:redhat:enterprise_linux:6"],"defaultStatus":"affected","packageName":"vim","product":"Red Hat Enterprise Linux 6","vendor":"Red Hat"},{"collectionURL":"https://access.redhat.com/downloads/content/package-browser/","cpes":["cpe:/a:redhat:hummingbird:1"],"defaultStatus":"affected","packageName":"vim","product":"Red Hat Hardened Images","vendor":"Red Hat"},{"collectionURL":"https://access.redhat.com/downloads/content/package-browser/","cpes":["cpe:/a:redhat:openshift:4"],"defaultStatus":"unaffected","packageName":"openshift/ose-rhel-coreos-8","product":"Red Hat OpenShift Container Platform 4","vendor":"Red Hat"}],"source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"configurations":[{"nodes":[{"cpeMatch":[{"criteria":"cpe:2.3:a:vim:vim:*:*:*:*:*:*:*:*","matchCriteriaId":"F06ADF1A-D6E5-4530-AFFA-83D781D33D74","versionEndExcluding":"9.2.0495","vulnerable":true}],"negate":false,"operator":"OR"}]}],"cveTags":[],"descriptions":[{"lang":"en","value":"Vim is an open source, command line text editor. Prior to version 9.2.0495, a Vimscript code injection vulnerability exists in s:NetrwBookHistSave() in the netrw plugin (runtime/pack/dist/opt/netrw/autoload/netrw.vim) when serializing browsed directory paths to the history file ~/.vim/.netrwhist. A directory name derived from the filesystem is interpolated into a single-quoted Vimscript string literal without escaping embedded single quotes, allowing a crafted directory name to break out of the string context and execute arbitrary Vimscript, including shell commands via system() and :!, the next time the history file is sourced. This issue has been patched in version 9.2.0495."}],"id":"CVE-2026-47162","lastModified":"2026-09-18T13:18:28.190","metrics":{"cvssMetricV31":[{"cvssData":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"HIGH","baseScore":8.8,"baseSeverity":"HIGH","confidentialityImpact":"HIGH","integrityImpact":"HIGH","privilegesRequired":"NONE","scope":"UNCHANGED","userInteraction":"REQUIRED","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","version":"3.1"},"exploitabilityScore":2.8,"impactScore":5.9,"source":"nvd@nist.gov","type":"Primary"},{"cvssData":{"attackComplexity":"LOW","attackVector":"LOCAL","availabilityImpact":"HIGH","baseScore":7.3,"baseSeverity":"HIGH","confidentialityImpact":"HIGH","integrityImpact":"HIGH","privilegesRequired":"LOW","scope":"UNCHANGED","userInteraction":"REQUIRED","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H","version":"3.1"},"exploitabilityScore":1.3,"impactScore":5.9,"source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","type":"Secondary"}],"cvssMetricV40":[{"cvssData":{"Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","Safety":"NOT_DEFINED","attackComplexity":"LOW","attackRequirements":"PRESENT","attackVector":"NETWORK","availabilityRequirement":"NOT_DEFINED","baseScore":7.3,"baseSeverity":"HIGH","confidentialityRequirement":"NOT_DEFINED","exploitMaturity":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","privilegesRequired":"LOW","providerUrgency":"NOT_DEFINED","subAvailabilityImpact":"NONE","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","userInteraction":"ACTIVE","valueDensity":"NOT_DEFINED","vectorString":"CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","version":"4.0","vulnAvailabilityImpact":"HIGH","vulnConfidentialityImpact":"HIGH","vulnIntegrityImpact":"HIGH","vulnerabilityResponseEffort":"NOT_DEFINED"},"source":"security-advisories@github.com","type":"Secondary"}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"id":"CVE-2026-47162","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"total"}],"role":"CISA Coordinator","timestamp":"2026-06-12T03:55:42.649076Z","version":"2.0.3"}}]},"published":"2026-06-11T19:16:44.160","references":[{"source":"security-advisories@github.com","tags":["Patch"],"url":"https://github.com/vim/vim/commit/f08ab2f4d7d2947c8dd6c179ae08ee6146a2694b"},{"source":"security-advisories@github.com","tags":["Product"],"url":"https://github.com/vim/vim/releases/tag/v9.2.0495"},{"source":"security-advisories@github.com","tags":["Vendor Advisory"],"url":"https://github.com/vim/vim/security/advisories/GHSA-crm5-rh6j-2c7c"},{"source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","url":"https://access.redhat.com/errata/RHSA-2026:38509"},{"source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","url":"https://access.redhat.com/errata/RHSA-2026:38510"},{"source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","url":"https://access.redhat.com/errata/RHSA-2026:38511"},{"source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","url":"https://access.redhat.com/errata/RHSA-2026:53371"},{"source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","url":"https://access.redhat.com/errata/RHSA-2026:54769"},{"source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","url":"https://access.redhat.com/errata/RHSA-2026:55431"},{"source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","url":"https://access.redhat.com/errata/RHSA-2026:58981"},{"source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","url":"https://access.redhat.com/errata/RHSA-2026:68711"},{"source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","url":"https://access.redhat.com/security/cve/CVE-2026-47162"},{"source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2487964"},{"source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","url":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-47162.json"}],"sourceIdentifier":"security-advisories@github.com","vulnStatus":"Modified","weaknesses":[{"description":[{"lang":"en","value":"CWE-74"},{"lang":"en","value":"CWE-94"}],"source":"security-advisories@github.com","type":"Secondary"},{"description":[{"lang":"en","value":"CWE-140"}],"source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","type":"Secondary"}]},"severity":"HIGH","source":"nvd","title":"Vim is an open source, command line text editor"}