CVE Wiki Pixee · CVE intelligence
← All CVEs

CVE-2026-34714

Critical · CVSS 9.2

Vim — Expression injection leading to OS command execution (CWE-78 / CWE-917) via %{expr} in tabpanel option missing P_MLE flag

CVSS
9.2
nvd
EPSS
KEV
No
Class
other
CWE-78, CWE-917

Description

Vim before 9.2.0272 allows code execution that happens immediately upon opening a crafted file in the default configuration, because %{expr} injection occurs with tabpanel lacking P_MLE.

Search profile — drives PoC discovery

Symbols tabpanelP_MLE%{expr}tabpaneloptp_tplset_string_optioncheck_tabpanel
Keywords CVE-2026-34714Vim tabpanel expression injectionVim %{expr} RCEVim code execution file openVim 9.2.0272GHSA-2gmj-rpqf-pxvhVim P_MLE tabpanelVim modeline injection
Versions: < 9.2.0272

References

Status: enriched · ingested 2026-06-25T18:00:38.000Z · profiled 2026-07-01T06:30:14.000Z