macvim-dev / macvim-dev/macvim

Multiple CVEs — including CVE-2026-34714 (fixed upstream in Vim 9.2.0272)

未关闭
#1,634 3 条评论 2 个 reaction 已指派 0 人 在 GitHub 查看

还没有人认领这个 Issue。

主要语言
Vim Script
星标
7.9k
派生
691
PR 合并指标
30 天内没有已合并 PR

描述

Current public MacVim releases are listed as:

  • r182: Vim 9.1.1887
  • r182.1 prerelease: Vim 9.1.2068

These versions predate multiple upstream Vim security fixes from 2026, including:

  • CVE-2026-28417, fixed in Vim 9.2.0073
  • CVE-2026-33412, fixed in Vim 9.2.0202
  • CVE-2026-34714, fixed in Vim 9.2.0272

Could you confirm whether these fixes were backported to MacVim, or whether an updated release is planned? CVE-2026-34714 looks especially relevant because it is triggered on opening a crafted file and mentions tabpanel.

贡献指南

打开贡献指南

从这里开始

  1. 先读完整个 Issue,再读项目的贡献指南。
  2. 在 Issue 下留言说明你要接手 —— 这能避免两个人做同样的事。
  3. Fork 仓库,在一个分支上完成修改。
  4. 提交 Pull Request,并在描述里引用这个 Issue 编号。

调研方向

首先,将列出的 MacVim 版本 r182 和 r182.1(prerelease)与修复了 CVE-2026-28417、CVE-2026-33412 和 CVE-2026-34714 的上游 Vim 版本进行比较。确认这些修复是否已包含,并记录是否计划进行 backport 或发布更新版本;该 issue 未指定文件或测试。

由索引模型根据 Issue 内容生成。

评估

技术栈
macos, vim
领域
desktop, release, security
Issue 类型
缺陷
难度
4/5
预计耗时
3-5 天
活跃度
冷清
描述清晰度
需要澄清
新手友好度
35/100

把新 issue 发到你的邮箱

精选适合新手参与的 GitHub issue 摘要。