Vim <9.2.0276 Modeline Sandbox Bypass OS Command Exec
CVE-2026-34982 Published on April 6, 2026
Vim modeline bypass via various options affects Vim < 9.2.0276
Vim is an open source, command line text editor. Prior to version 9.2.0276, a modeline sandbox bypass in Vim allows arbitrary OS command execution when a user opens a crafted file. The `complete`, `guitabtooltip` and `printheader` options are missing the `P_MLE` flag, allowing a modeline to be executed. Additionally, the `mapset()` function lacks a `check_secure()` call, allowing it to be abused from sandboxed expressions. Commit 9.2.0276 fixes the issue.
Vulnerability Analysis
CVE-2026-34982 is exploitable with local system access, requires user interaction. This vulnerability is considered to have a low attack complexity. The potential impact of an exploit of this vulnerability is considered to have a high impact on confidentiality and integrity, and no impact on availability.
Weakness Type
What is a Shell injection Vulnerability?
The software constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component.
CVE-2026-34982 has been classified to as a Shell injection vulnerability or weakness.
Products Associated with CVE-2026-34982
You can be notified by email with stack.watch whenever vulnerabilities like CVE-2026-34982 are published in these products:
Affected Versions
vim:- Version < 9.2.0276 is affected.
- Version 2:9.1.083-6.el10_1.4 and below * is unaffected.
- Version 2:9.1.083-9.el10_2.2 and below * is unaffected.
- Version 2:9.1.083-5.el10_0.3 and below * is unaffected.
- Version 2:8.0.1763-22.el8_10.3 and below * is unaffected.
- Version 2:8.0.1763-15.el8_4.2 and below * is unaffected.
- Version 2:8.0.1763-15.el8_4.2 and below * is unaffected.
- Version 2:8.0.1763-19.el8_6.6 and below * is unaffected.
- Version 2:8.0.1763-19.el8_6.6 and below * is unaffected.
- Version 2:8.0.1763-20.el8_8.2 and below * is unaffected.
- Version 2:8.0.1763-20.el8_8.2 and below * is unaffected.
- Version 2:8.2.2637-23.el9_7.3 and below * is unaffected.
- Version 2:8.2.2637-26.el9_8.4 and below * is unaffected.
- Version 2:8.2.2637-20.el9_2.2 and below * is unaffected.
- Version 2:8.2.2637-20.el9_4.3 and below * is unaffected.
- Version 2:8.2.2637-22.el9_6.3 and below * is unaffected.
- Version 1782951051 and below * is unaffected.
- Version 1782951012 and below * is unaffected.
- Version 1782951244 and below * is unaffected.
- Version 1782352950 and below * is unaffected.
- Version 1782352919 and below * is unaffected.
- Version 1782353093 and below * is unaffected.
- Version 1782352847 and below * is unaffected.
- Version 1780420428 and below * is unaffected.
- Version 1779798159 and below * is unaffected.
- Version 1779798164 and below * is unaffected.
- Version 1779798165 and below * is unaffected.
- Version 1779798222 and below * is unaffected.
Exploit Probability
EPSS (Exploit Prediction Scoring System) scores estimate the probability that a vulnerability will be exploited in the wild within the next 30 days. The percentile shows you how this score compares to all other vulnerabilities.