macvim-dev / macvim-dev/macvim
[Security] MacVim affected by CVE-2026-46483 — tar#Vimuntar() command injection via shellescape (vim < 9.2.0479)
Personne n'a encore pris cette issue.
- Langage dominant
- Vim Script
- Étoiles
- 7.9k
- Forks
- 691
- Métriques de merge des PR
- Aucune PR mergée en 30 j
Description
[Security] MacVim affected by CVE-2026-46483 — tar#Vimuntar() command injection via shellescape (vim < 9.2.0479)
Summary
MacVim bundles the vim source at version 9.2 (patches 1-332 in the current build), which is
below the patched version 9.2.0479 that fixes CVE-2026-46483.
Vulnerability Details
- Upstream CVE: CVE-2026-46483
- Inherited from:
vim/vim - Affected code:
runtime/autoload/tar.vim, functiontar#Vimuntar() - Vulnerability type: CWE-78 — OS Command Injection
- Fixed in: vim 9.2.0479 (commit
3fb5e58fbc63d86a3e65f1a141b0d67af2aa38a1)
Root Cause
In tar#Vimuntar() (runtime/autoload/tar.vim), the function decompresses a .tgz tarball
using :!gunzip and tar. The filename is escaped using shellescape(tartail) without
the second argument 1:
" runtime/autoload/tar.vim (macvim r183, around line 815)
if tartail =~ '\.tgz'
if executable("gunzip")
silent exe "!gunzip ".shellescape(tartail)
When vim's :! command processes the command string, the ! character in the filename
is interpreted by vim's command-line history substitution BEFORE the shell sees it.
shellescape(x, 0) (the default) does not escape ! for the vim :! context, while
shellescape(x, 1) does.
If an attacker can name a .tgz file to contain !command, and trick a user into
running tar#Vimuntar() on it, the embedded command is executed.
Affected MacVim Code
MacVim's runtime/autoload/tar.vim contains the vulnerable tar#Vimuntar() function at
line 784. The fix changes shellescape(tartail) to shellescape(tartail, 1) throughout
the function.
Note: neovim does NOT have the tar#Vimuntar() function and is not affected by this
specific vulnerability.
Affected MacVim Version
MacVim r183 (vim 9.2 patches 1-332) — current HEAD as of 2026-05-18.
The fix commit 3fb5e58fbc63d86a3e65f1a141b0d67af2aa38a1 from vim/vim is not present
in the macvim-dev/macvim repository:
git log --all --oneline | grep 3fb5e58f # returns no output
Suggested Fix
Merge or cherry-pick vim/vim patches up to at least 9.2.0479:
The fix changes shellescape(tartail) to shellescape(tartail, 1) which properly escapes
! characters for vim's :! command context.
References
- CVE: https://nvd.nist.gov/vuln/detail/CVE-2026-46483
- Upstream advisory: https://github.com/vim/vim/security/advisories/GHSA-2fpv-9ff7-xg5w
- Upstream fix commit: https://github.com/vim/vim/commit/3fb5e58fbc63d86a3e65f1a141b0d67af2aa38a1
Guide de contribution
Ouvrir le guide de contribution
Par où commencer
- Lisez l'issue en entier, puis le guide de contribution du projet.
- Signalez en commentaire que vous la prenez — cela évite que deux personnes fassent le même travail.
- Forkez le dépôt et travaillez sur une branche.
- Ouvrez une pull request qui référence le numéro de l'issue.
Piste de recherche
Commencez par runtime/autoload/tar.vim et examinez tar#Vimuntar(), en particulier la gestion de .tgz autour de la ligne concernée. Comparez la fonction avec le commit Vim 3fb5e58fbc63d86a3e65f1a141b0d67af2aa38a1 et vérifiez que MacVim inclut le correctif upstream jusqu’à Vim 9.2.0479 ; le travail est terminé lorsque la fonction vulnérable est mise à jour et que la modification est couverte par une vérification appropriée.
Rédigé par le modèle d'indexation à partir du texte de l'issue.
Évaluation
- Stack technique
- macos, vim
- Domaine
- operating-systems, security
- Type d'issue
- Bug
- Difficulté
- 4/5
- Temps estimé
- 3-5 jours
- Activité
- Calme
- Clarté
- Clairement spécifiée
- Accessibilité débutants
- 45/100