9.2
/ 10
CRITICAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:L
Description
Vim before 9.2.0272 allows code execution that happens immediately upon opening a crafted file in the default configuration, because %{expr} injection occurs with tabpanel lacking P_MLE.
Basic Information
ID
CVE-2026-34714
Source
mitre
Published
Mar 30, 2026 at 18:27
Modified
Apr 3, 2026 at 11:15
Affected Product
Vendor
Vim
Product
Vim
Affected Versions
Vim Vim 0