THREAT OPS › Threat News › [NVD] CVE-2026-47162 (HIGH 8.8) — Vim is an open source, command line text editor. Prior to version 9.2.0495, a Vimscript code injection vulnerability exists in s:NetrwBookHistSave() in the netrw plugin (runtime/pack/dist/opt/netrw/autoload/netrw.vim) when serializing browsed directory paths to the history file ~
[NVD] CVE-2026-47162 (HIGH 8.8) — Vim is an open source, command line text editor. Prior to version 9.2.0495, a Vimscript code injection vulnerability exists in s:NetrwBookHistSave() in the netrw plugin (runtime/pack/dist/opt/netrw/autoload/netrw.vim) when serializing browsed directory paths to the history file ~
CVE-2026-47162 CVSS: 8.8 HIGH Published: 2026-06-11T19:16:44.160
Vim is an open source, command line text editor. Prior to version 9.2.0495, a Vimscript code injection vulnerability exists in s:NetrwBookHistSave() in the netrw plugin (runtime/pack/dist/opt/netrw/autoload/netrw.vim) when serializing browsed directory paths to the history file ~/.vim/.netrwhist. A directory name derived from the fi
Indicators of compromise
- CVE-2026-47162cve
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-47162