macvim-dev / macvim-dev/macvim
[Security] MacVim affected by CVE-2026-41411 — tag file command injection (vim < 9.2.0357)
まだ誰も着手していません。
- 主要言語
- Vim Script
- スター
- 7.9k
- フォーク
- 691
- PR マージ指標
- 30日以内にマージされた PR はありません
説明
[Security] MacVim affected by CVE-2026-41411 — tag file command injection (vim < 9.2.0357)
Summary
MacVim bundles the vim source at version 9.2 (patches 1-332 in the current build), which is
below the patched version 9.2.0357 that fixes CVE-2026-41411.
Vulnerability Details
- Upstream CVE: CVE-2026-41411
- Inherited from:
vim/vim - Affected code: tag file processing (wildcard expansion of filename fields)
- Vulnerability type: CWE-78 — OS Command Injection
- Fixed in: vim 9.2.0357 (commit
c78194e41d5a0b05b0ddf383b6679b1503f977fb)
Root Cause
Prior to vim 9.2.0357, when resolving a tag, the filename field from the tags file is passed
through wildcard expansion to resolve environment variables and wildcards. If a crafted tags
file contains a filename with shell metacharacters or backtick-enclosed commands, those
commands are executed when the tag is resolved.
An attacker who can influence the tags file (e.g., via a malicious project or downloaded
code repository) can achieve arbitrary command execution when the victim opens a file and
navigates to a tag definition.
Affected MacVim Version
MacVim r183 (vim 9.2 patches 1-332) — current HEAD as of 2026-05-18.
The fix commit c78194e41d5a0b05b0ddf383b6679b1503f977fb from vim/vim is not present
in the macvim-dev/macvim repository:
git log --all --oneline | grep c78194e # returns no output
Suggested Fix
Merge or cherry-pick vim/vim patches up to at least 9.2.0357:
References
- CVE: https://nvd.nist.gov/vuln/detail/CVE-2026-41411
- Upstream advisory: https://github.com/vim/vim/security/advisories/GHSA-7rvw-9w8x-xhwx
- Upstream fix commit: https://github.com/vim/vim/commit/c78194e41d5a0b05b0ddf383b6679b1503f977fb
コントリビューションガイド
はじめの一歩
- issue を最後まで読み、次にプロジェクトのコントリビューションガイドを読みます。
- 着手することを issue にコメントします — 二人が同じ作業をするのを防げます。
- リポジトリをフォークし、ブランチを切って変更します。
- issue 番号を参照したプルリクエストを送ります。
調査の方向性
まず、同梱されている Vim のソースとその履歴を調査し、次にリポジトリを upstream のコミット c78194e41d5a0b05b0ddf383b6679b1503f977fb と比較してください。issue では、現在 git log で一致するコミットが見つからないと記載されています。同梱されている Vim パッチを少なくとも 9.2.0357 に更新し、MacVim のビルドに upstream の tag-file セキュリティ修正が組み込まれていることを確認してください。
索引モデルが issue の本文から書いたものです。
評価
- 技術スタック
- macos, vim
- 領域
- desktop, security
- issue の種類
- バグ
- 難易度
- 4/5
- 見積もり時間
- 3〜5日
- 活発さ
- 静か
- 明瞭さ
- おおむね明確
- 初心者へのやさしさ
- 55/100