macvim-dev / macvim-dev/macvim
[Security] MacVim affected by GHSA-2fpv-9ff7-xg5w — tar.vim command injection via crafted .tgz filename (vim < 9.2.0479)
Dieses Issue hat noch niemand übernommen.
- Vorherrschende Sprache
- Vim Script
- Sterne
- 7.9k
- Forks
- 691
- PR-Merge-Kennzahlen
- Keine gemergten PRs in 30 T.
Beschreibung
Summary
MacVim bundles runtime/autoload/tar.vim containing tar#Vimuntar(), which builds :!gunzip and :!gzip -d shell commands using shellescape(tartail) without the {special} flag. On Unix-like systems, Vim re-expands cmdline-special characters (%, #, !, etc.) before passing a :! command to the shell, so a crafted .tgz filename can inject arbitrary shell commands. The fix from vim 9.2.0479 (3fb5e58fbc63d86a3e65f1a141b0d67af2aa38a1) has not been applied to macvim r183.
Vulnerability Details
- GHSA: GHSA-2fpv-9ff7-xg5w
- CVE: CVE-2026-46483
- Upstream fix (vim): 9.2.0479 (commit
3fb5e58fbc63d86a3e65f1a141b0d67af2aa38a1, 2026-05-14) - Affected code:
runtime/autoload/tar.vim—tar#Vimuntar()function - Vulnerability type: CWE-78 — OS Command Injection
Root Cause
In tar#Vimuntar(), the archive tail filename (tartail = expand("%:t")) is passed to :! commands via shellescape() without the required second argument ({special}=1):
" runtime/autoload/tar.vim lines 809-812 (macvim r183)
if executable("gunzip")
silent exe "!gunzip ".shellescape(tartail)
elseif executable("gzip")
silent exe "!gzip -d ".shellescape(tartail)
As documented in :help shellescape(), when using the result in a :! command, the second argument must be non-zero so that Vim cmdline-special characters are also escaped. Without it, a filename like ';%$(touch pwned)'.tgz causes Vim to expand % and ! before the shell sees the argument.
Suggested Fix
Merge vim patches up to at least 9.2.0479. The fix adds , 1 to both shellescape() calls:
" Fixed (vim 9.2.0479):
if executable("gunzip")
silent exe "!gunzip ".shellescape(tartail, 1)
elseif executable("gzip")
silent exe "!gzip -d ".shellescape(tartail, 1)
References
Beitragsleitfaden
Erste Schritte
- Lies das ganze Issue und danach den Beitragsleitfaden des Projekts.
- Schreib ins Issue, dass du es übernimmst — das erspart doppelte Arbeit.
- Forke das Repository und arbeite in einem Branch.
- Öffne einen Pull Request, der die Issue-Nummer nennt.
Rechercherichtung
Beginnen Sie in runtime/autoload/tar.vim bei tar#Vimuntar() und vergleichen Sie die beiden shellescape()-Aufrufe mit dem Upstream-Vim-Commit 3fb5e58fbc63d86a3e65f1a141b0d67af2aa38a1. Wenden Sie den Upstream-Sicherheitsfix an und überprüfen Sie, dass ein präparierter .tgz-Dateiname keine Befehlsinjektion mehr über den gunzip- oder gzip-Pfad ermöglicht.
Vom Indexierungsmodell aus dem Issue-Text verfasst.
Bewertung
- Tech-Stack
- macos, vim
- Bereich
- security
- Issue-Typ
- Bug
- Schwierigkeit
- 2/5
- Geschätzter Aufwand
- 1-3 Stunden
- Aktivitätsstatus
- Ruhig
- Klarheit
- Klar beschrieben
- Anfängerfreundlichkeit
- 76/100