THREATOPS
THREAT OPSThreat News › [NVD] CVE-2026-47162 (HIGH 8.8) — Vim is an open source, command line text editor. Prior to version 9.2.0495, a Vimscript code injection vulnerability exists in s:NetrwBookHistSave() in the netrw plugin (runtime/pack/dist/opt/netrw/autoload/netrw.vim) when serializing browsed directory paths to the history file ~

[NVD] CVE-2026-47162 (HIGH 8.8) — Vim is an open source, command line text editor. Prior to version 9.2.0495, a Vimscript code injection vulnerability exists in s:NetrwBookHistSave() in the netrw plugin (runtime/pack/dist/opt/netrw/autoload/netrw.vim) when serializing browsed directory paths to the history file ~

lownvdPublished 2026-06-11

CVE-2026-47162 CVSS: 8.8 HIGH Published: 2026-06-11T19:16:44.160

Vim is an open source, command line text editor. Prior to version 9.2.0495, a Vimscript code injection vulnerability exists in s:NetrwBookHistSave() in the netrw plugin (runtime/pack/dist/opt/netrw/autoload/netrw.vim) when serializing browsed directory paths to the history file ~/.vim/.netrwhist. A directory name derived from the fi

Indicators of compromise

Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-47162