Vim is an open source, command line text editor. Prior to version 9.2.0276, a modeline sandbox bypass in Vim allows arbitrary OS command execution when a user opens a crafted file. The `complete`, `guitabtooltip` and `printheader` options are missing the `P_MLE` flag, allowing a modeline to be executed. Additionally, the `mapset()` function lacks a `check_secure()` call, allowing it to be abused from sandboxed expressions. Commit 9.2.0276 fixes the issue.

Project Subscriptions

Vendors Products
Advisories
Source ID Title
Ubuntu USN Ubuntu USN USN-8171-1 Vim vulnerabilities
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

References
Link Providers
http://www.openwall.com/lists/oss-security/2026/04/01/1 cve-icon cve-icon
https://access.redhat.com/errata/RHSA-2026:11389 cve-icon
https://access.redhat.com/errata/RHSA-2026:11509 cve-icon
https://access.redhat.com/errata/RHSA-2026:11510 cve-icon
https://access.redhat.com/errata/RHSA-2026:19073 cve-icon
https://access.redhat.com/errata/RHSA-2026:19224 cve-icon
https://access.redhat.com/errata/RHSA-2026:21275 cve-icon
https://access.redhat.com/errata/RHSA-2026:22634 cve-icon
https://access.redhat.com/errata/RHSA-2026:28049 cve-icon
https://access.redhat.com/errata/RHSA-2026:28050 cve-icon
https://access.redhat.com/errata/RHSA-2026:28133 cve-icon
https://access.redhat.com/errata/RHSA-2026:30078 cve-icon
https://access.redhat.com/errata/RHSA-2026:30087 cve-icon
https://access.redhat.com/errata/RHSA-2026:30088 cve-icon
https://access.redhat.com/errata/RHSA-2026:30089 cve-icon
https://access.redhat.com/errata/RHSA-2026:30900 cve-icon
https://access.redhat.com/errata/RHSA-2026:33453 cve-icon
https://access.redhat.com/errata/RHSA-2026:34476 cve-icon
https://access.redhat.com/errata/RHSA-2026:34477 cve-icon
https://access.redhat.com/errata/RHSA-2026:36004 cve-icon
https://access.redhat.com/errata/RHSA-2026:36005 cve-icon
https://access.redhat.com/errata/RHSA-2026:36006 cve-icon
https://access.redhat.com/security/cve/CVE-2026-34982 cve-icon
https://bugzilla.redhat.com/show_bug.cgi?id=2455400 cve-icon
https://github.com/vim/vim/commit/75661a66a1db1e1f3f1245c615 cve-icon cve-icon cve-icon
https://github.com/vim/vim/releases/tag/v9.2.0276 cve-icon cve-icon cve-icon
https://github.com/vim/vim/security/advisories/GHSA-8h6p-m6gr-mpw9 cve-icon cve-icon cve-icon
https://nvd.nist.gov/vuln/detail/CVE-2026-34982 cve-icon
https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-34982.json cve-icon
https://www.cve.org/CVERecord?id=CVE-2026-34982 cve-icon
History

Wed, 22 Apr 2026 20:15:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:vim:vim:*:*:*:*:*:*:*:*

Tue, 07 Apr 2026 00:00:00 +0000

Type Values Removed Values Added
First Time appeared Vim
Vim vim
Vendors & Products Vim
Vim vim
References
Metrics threat_severity

None

threat_severity

Important


Mon, 06 Apr 2026 16:45:00 +0000

Type Values Removed Values Added
References
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 06 Apr 2026 15:30:00 +0000

Type Values Removed Values Added
Description Vim is an open source, command line text editor. Prior to version 9.2.0276, a modeline sandbox bypass in Vim allows arbitrary OS command execution when a user opens a crafted file. The `complete`, `guitabtooltip` and `printheader` options are missing the `P_MLE` flag, allowing a modeline to be executed. Additionally, the `mapset()` function lacks a `check_secure()` call, allowing it to be abused from sandboxed expressions. Commit 9.2.0276 fixes the issue.
Title Vim modeline bypass via various options affects Vim < 9.2.0276
Weaknesses CWE-78
References
Metrics cvssV3_1

{'score': 8.2, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-07-15T01:03:29.473Z

Reserved: 2026-03-31T19:38:31.617Z

Link: CVE-2026-34982

cve-icon Vulnrichment

Updated: 2026-04-06T15:19:17.901Z

cve-icon NVD

Status : Modified

Published: 2026-04-06T16:16:38.777

Modified: 2026-07-15T02:20:36.983

Link: CVE-2026-34982

cve-icon Redhat

Severity : Important

Publid Date: 2026-04-06T15:16:48Z

Links: CVE-2026-34982 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-04-06T21:32:23Z

Weaknesses