macvim-dev / macvim-dev/macvim

[Security] MacVim affected by GHSA-2fpv-9ff7-xg5w — tar.vim command injection via crafted .tgz filename (vim < 9.2.0479)

Open Beginner friendly
#1,655 0 comments 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

Dominant language
Vim Script
Stars
7.9k
Forks
691
PR merge metrics
No merged PRs in 30d

Description

Summary

MacVim bundles runtime/autoload/tar.vim containing tar#Vimuntar(), which builds :!gunzip and :!gzip -d shell commands using shellescape(tartail) without the {special} flag. On Unix-like systems, Vim re-expands cmdline-special characters (%, #, !, etc.) before passing a :! command to the shell, so a crafted .tgz filename can inject arbitrary shell commands. The fix from vim 9.2.0479 (3fb5e58fbc63d86a3e65f1a141b0d67af2aa38a1) has not been applied to macvim r183.

Vulnerability Details

  • GHSA: GHSA-2fpv-9ff7-xg5w
  • CVE: CVE-2026-46483
  • Upstream fix (vim): 9.2.0479 (commit 3fb5e58fbc63d86a3e65f1a141b0d67af2aa38a1, 2026-05-14)
  • Affected code: runtime/autoload/tar.vimtar#Vimuntar() function
  • Vulnerability type: CWE-78 — OS Command Injection

Root Cause

In tar#Vimuntar(), the archive tail filename (tartail = expand("%:t")) is passed to :! commands via shellescape() without the required second argument ({special}=1):

" runtime/autoload/tar.vim lines 809-812 (macvim r183)
if executable("gunzip")
  silent exe "!gunzip ".shellescape(tartail)
elseif executable("gzip")
  silent exe "!gzip -d ".shellescape(tartail)

As documented in :help shellescape(), when using the result in a :! command, the second argument must be non-zero so that Vim cmdline-special characters are also escaped. Without it, a filename like ';%$(touch pwned)'.tgz causes Vim to expand % and ! before the shell sees the argument.

Suggested Fix

Merge vim patches up to at least 9.2.0479. The fix adds , 1 to both shellescape() calls:

" Fixed (vim 9.2.0479):
if executable("gunzip")
  silent exe "!gunzip ".shellescape(tartail, 1)
elseif executable("gzip")
  silent exe "!gzip -d ".shellescape(tartail, 1)

References

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

Start in runtime/autoload/tar.vim at tar#Vimuntar() and compare the two shellescape() calls with upstream Vim commit 3fb5e58fbc63d86a3e65f1a141b0d67af2aa38a1. Apply the upstream security fix and verify that a crafted .tgz filename no longer permits command injection through the gunzip or gzip path.

Written by the indexing model from the issue text.

Assessment

Tech stack
macos, vim
Domain
security
Issue type
Bug
Difficulty
2/5
Estimated time
1-3 hours
Activity status
Quiet
Clarity
Clearly specified
Newbie friendliness
76/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.