CVE-2026-39881

Public on 2026-04-08
Modified on 2026-04-10
Description
Ex command injection in Vim's NetBeans integration before v9.2.0316. The netbeans defineAnnoType command passes typeName, fg and bg unsanitized to coloncmd(), allowing a malicious NetBeans server to inject arbitrary Ex commands via '|'. Similarly, specialKeys does not validate key tokens before building a map command.
Severity
Medium severity
Medium
See what this means
CVSS v3 Base Score
5.0
See breakdown

Affected Packages

Platform Package Release Date Advisory Status
Amazon Linux 2 - Core vim Pending Fix
Amazon Linux 2023 vim Pending Fix

CVSS Scores

Score Type Score Vector
Amazon Linux CVSSv3 5.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:L/I:H/A:N