macvim-dev / macvim-dev/macvim

[Security] MacVim affected by CVE-2026-44656 — :find completion backtick OS command injection (vim < 9.2.0435)

未关闭
#1,648 0 条评论 0 个 reaction 已指派 0 人 在 GitHub 查看

还没有人认领这个 Issue。

主要语言
Vim Script
星标
7.9k
派生
691
PR 合并指标
30 天内没有已合并 PR

描述

[Security] MacVim affected by CVE-2026-44656 — :find completion backtick OS command injection (vim < 9.2.0435)

Summary

MacVim bundles the vim source at version 9.2 (patches 1-332 in the current build), which is
below the patched version 9.2.0435 that fixes CVE-2026-44656.

Vulnerability Details

  • Upstream CVE: CVE-2026-44656
  • Inherited from: vim/vim
  • Affected code: :find command-line completion with path option
  • Vulnerability type: CWE-78 — OS Command Injection
  • Fixed in: vim 9.2.0435 (commit 190cb3c2b9c769a3972bcfd991a7b5b6cb771ef0)

Root Cause

Prior to vim 9.2.0435, an OS command injection vulnerability exists in Vim's :find
command-line completion. When the path option contains backtick-enclosed shell commands
(e.g., path= cmd``), those commands are executed during filename completion. Because the pathoption can be set via modelines or project-local configuration files, an attacker who controls such files can execute arbitrary commands when the victim uses tab-completion with:find`.

Affected MacVim Version

MacVim r183 (vim 9.2 patches 1-332) — current HEAD as of 2026-05-18.

The fix commit 190cb3c2b9c769a3972bcfd991a7b5b6cb771ef0 from vim/vim is not present
in the macvim-dev/macvim repository:

git log --all --oneline | grep 190cb3c2  # returns no output

Suggested Fix

Merge or cherry-pick vim/vim patches up to at least 9.2.0435:

References

贡献指南

打开贡献指南

从这里开始

  1. 先读完整个 Issue,再读项目的贡献指南。
  2. 在 Issue 下留言说明你要接手 —— 这能避免两个人做同样的事。
  3. Fork 仓库,在一个分支上完成修改。
  4. 提交 Pull Request,并在描述里引用这个 Issue 编号。

调研方向

首先检查捆绑的 Vim 9.2 补丁,并将 git log --all --oneline | grep 190cb3c2 与上游提交 190cb3c2b9c769a3972bcfd991a7b5b6cb771ef0 进行比较。将捆绑的源代码更新到 Vim 9.2.0435 或更高版本,然后验证该修复已包含在 MacVim 构建中,并且受影响的 :find 补全行为不再存在漏洞。

由索引模型根据 Issue 内容生成。

评估

技术栈
macos, vim
领域
desktop, security
Issue 类型
缺陷
难度
4/5
预计耗时
3-5 天
活跃度
冷清
描述清晰度
描述清楚
新手友好度
48/100

把新 issue 发到你的邮箱

精选适合新手参与的 GitHub issue 摘要。