What is CVE-2026-51400?
A vulnerability in Vim's `vms_fixfilename()` function allows a local attacker to execute arbitrary code through crafted filename manipulation. This affects Vim Project version 9.2.0389 and earlier. It is recommended to update to the latest patched version.
Azərbaycanca: Vim mətn redaktorunda `vms_fixfilename()` funksiyasında boşluq aşkarlanıb. Bu, lokal hücumçuya xüsusi fayl adı manipulyasiyası vasitəsilə ixtiyari kod icra etməyə imkan verir. Təhlükəsizlik üçün Vim 9.2.0389 və daha əvvəlki versiyaları ən son yamaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-94
FAQ2
What can CVE-2026-51400 in Vim lead to?
This vulnerability allows a local attacker to execute arbitrary code through crafted filename manipulation.
Which Vim versions are affected by CVE-2026-51400?
This vulnerability affects Vim version 9.2.0389 and earlier.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.