macvim-dev / macvim-dev/macvim
[Security] MacVim affected by GHSA-2fpv-9ff7-xg5w — tar.vim command injection via crafted .tgz filename (vim < 9.2.0479)
まだ誰も着手していません。
- 主要言語
- Vim Script
- スター
- 7.9k
- フォーク
- 691
- PR マージ指標
- 30日以内にマージされた PR はありません
説明
Summary
MacVim bundles runtime/autoload/tar.vim containing tar#Vimuntar(), which builds :!gunzip and :!gzip -d shell commands using shellescape(tartail) without the {special} flag. On Unix-like systems, Vim re-expands cmdline-special characters (%, #, !, etc.) before passing a :! command to the shell, so a crafted .tgz filename can inject arbitrary shell commands. The fix from vim 9.2.0479 (3fb5e58fbc63d86a3e65f1a141b0d67af2aa38a1) has not been applied to macvim r183.
Vulnerability Details
- GHSA: GHSA-2fpv-9ff7-xg5w
- CVE: CVE-2026-46483
- Upstream fix (vim): 9.2.0479 (commit
3fb5e58fbc63d86a3e65f1a141b0d67af2aa38a1, 2026-05-14) - Affected code:
runtime/autoload/tar.vim—tar#Vimuntar()function - Vulnerability type: CWE-78 — OS Command Injection
Root Cause
In tar#Vimuntar(), the archive tail filename (tartail = expand("%:t")) is passed to :! commands via shellescape() without the required second argument ({special}=1):
" runtime/autoload/tar.vim lines 809-812 (macvim r183)
if executable("gunzip")
silent exe "!gunzip ".shellescape(tartail)
elseif executable("gzip")
silent exe "!gzip -d ".shellescape(tartail)
As documented in :help shellescape(), when using the result in a :! command, the second argument must be non-zero so that Vim cmdline-special characters are also escaped. Without it, a filename like ';%$(touch pwned)'.tgz causes Vim to expand % and ! before the shell sees the argument.
Suggested Fix
Merge vim patches up to at least 9.2.0479. The fix adds , 1 to both shellescape() calls:
" Fixed (vim 9.2.0479):
if executable("gunzip")
silent exe "!gunzip ".shellescape(tartail, 1)
elseif executable("gzip")
silent exe "!gzip -d ".shellescape(tartail, 1)
References
コントリビューションガイド
はじめの一歩
- issue を最後まで読み、次にプロジェクトのコントリビューションガイドを読みます。
- 着手することを issue にコメントします — 二人が同じ作業をするのを防げます。
- リポジトリをフォークし、ブランチを切って変更します。
- issue 番号を参照したプルリクエストを送ります。
調査の方向性
runtime/autoload/tar.vim の tar#Vimuntar() から始め、2 つの shellescape() 呼び出しを upstream の Vim コミット 3fb5e58fbc63d86a3e65f1a141b0d67af2aa38a1 と比較します。upstream のセキュリティ修正を適用し、細工した .tgz ファイル名によって gunzip または gzip パス経由のコマンドインジェクションができなくなったことを検証します。
索引モデルが issue の本文から書いたものです。
評価
- 技術スタック
- macos, vim
- 領域
- security
- issue の種類
- バグ
- 難易度
- 2/5
- 見積もり時間
- 1〜3時間
- 活発さ
- 静か
- 明瞭さ
- 明確に書かれている
- 初心者へのやさしさ
- 76/100