What is CVE-2026-43961?
A critical vulnerability was discovered in the netrw plugin of the Vim text editor. A specially crafted filename containing quote characters and expression fragments can lead to arbitrary Vimscript execution during mark/unmark operations. This flaw can be leveraged to run shell commands with the user's privileges, so updating Vim to the latest version is recommended.
Azərbaycanca: Vim mətn redaktorunun netrw plaqinində kritik bir boşluq aşkarlanıb. Tərkibində dırnaq işarələri və ifadə fraqmentləri olan xüsusi hazırlanmış fayl adı, işarələmə əməliyyatları zamanı özbaşına Vimscript kodunun icrasına səbəb ola bilər. Bu zəiflik vasitəsilə təcavüzkar istifadəçinin icazələri ilə shell əmrləri işlədə bilər, buna görə Vim-i ən son versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-94
FAQ1
How can the CVE-2026-43961 vulnerability in the Vim netrw plugin be exploited?
A specially crafted filename containing quote characters and expression fragments can trigger arbitrary Vimscript execution during netrw mark/unmark operations. This allows an attacker to run shell commands with the user's privileges.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.