macvim-dev / macvim-dev/macvim

[Security] MacVim affected by GHSA-2fpv-9ff7-xg5w — tar.vim command injection via crafted .tgz filename (vim < 9.2.0479)

オープン 初心者向け
#1,655 コメント 0 件 リアクション 0 件 担当者 0 名 GitHub で見る

まだ誰も着手していません。

主要言語
Vim Script
スター
7.9k
フォーク
691
PR マージ指標
30日以内にマージされた PR はありません

説明

Summary

MacVim bundles runtime/autoload/tar.vim containing tar#Vimuntar(), which builds :!gunzip and :!gzip -d shell commands using shellescape(tartail) without the {special} flag. On Unix-like systems, Vim re-expands cmdline-special characters (%, #, !, etc.) before passing a :! command to the shell, so a crafted .tgz filename can inject arbitrary shell commands. The fix from vim 9.2.0479 (3fb5e58fbc63d86a3e65f1a141b0d67af2aa38a1) has not been applied to macvim r183.

Vulnerability Details

  • GHSA: GHSA-2fpv-9ff7-xg5w
  • CVE: CVE-2026-46483
  • Upstream fix (vim): 9.2.0479 (commit 3fb5e58fbc63d86a3e65f1a141b0d67af2aa38a1, 2026-05-14)
  • Affected code: runtime/autoload/tar.vimtar#Vimuntar() function
  • Vulnerability type: CWE-78 — OS Command Injection

Root Cause

In tar#Vimuntar(), the archive tail filename (tartail = expand("%:t")) is passed to :! commands via shellescape() without the required second argument ({special}=1):

" runtime/autoload/tar.vim lines 809-812 (macvim r183)
if executable("gunzip")
  silent exe "!gunzip ".shellescape(tartail)
elseif executable("gzip")
  silent exe "!gzip -d ".shellescape(tartail)

As documented in :help shellescape(), when using the result in a :! command, the second argument must be non-zero so that Vim cmdline-special characters are also escaped. Without it, a filename like ';%$(touch pwned)'.tgz causes Vim to expand % and ! before the shell sees the argument.

Suggested Fix

Merge vim patches up to at least 9.2.0479. The fix adds , 1 to both shellescape() calls:

" Fixed (vim 9.2.0479):
if executable("gunzip")
  silent exe "!gunzip ".shellescape(tartail, 1)
elseif executable("gzip")
  silent exe "!gzip -d ".shellescape(tartail, 1)

References

コントリビューションガイド

コントリビューションガイドを開く

はじめの一歩

  1. issue を最後まで読み、次にプロジェクトのコントリビューションガイドを読みます。
  2. 着手することを issue にコメントします — 二人が同じ作業をするのを防げます。
  3. リポジトリをフォークし、ブランチを切って変更します。
  4. issue 番号を参照したプルリクエストを送ります。

調査の方向性

runtime/autoload/tar.vim の tar#Vimuntar() から始め、2 つの shellescape() 呼び出しを upstream の Vim コミット 3fb5e58fbc63d86a3e65f1a141b0d67af2aa38a1 と比較します。upstream のセキュリティ修正を適用し、細工した .tgz ファイル名によって gunzip または gzip パス経由のコマンドインジェクションができなくなったことを検証します。

索引モデルが issue の本文から書いたものです。

評価

技術スタック
macos, vim
領域
security
issue の種類
バグ
難易度
2/5
見積もり時間
1〜3時間
活発さ
静か
明瞭さ
明確に書かれている
初心者へのやさしさ
76/100

新しい issue をメールで受け取る

初心者向けの GitHub issue を短くまとめたダイジェスト。