macvim-dev / macvim-dev/macvim

[Security] MacVim affected by GHSA-85ch-p2qr-m5gx — netrw OS command injection via sftp:/file: URL tempfile suffix (vim < 9.2.0383)

Open Beginner friendly
#1,657 0 comments 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

Dominant language
Vim Script
Stars
7.9k
Forks
691
PR merge metrics
No merged PRs in 30d

Description

Summary

MacVim bundles the netrw plugin (runtime/pack/dist/opt/netrw/autoload/netrw.vim) which passes an unescaped tmpfile variable to a shell command when fetching remote files via sftp:// or file: URLs. A crafted URL with a shell metacharacter in the filename suffix causes arbitrary command execution. The fix from vim 9.2.0383 (405e2fb6) has not been applied to macvim r183.

Vulnerability Details

  • GHSA: GHSA-85ch-p2qr-m5gx
  • CVE: CVE-2026-42307
  • Upstream fix (vim): 9.2.0383 (commit 405e2fb6c2e35e09cb64e0f92c1efdafd6b3978a, 2026-04-21)
  • Affected code: runtime/pack/dist/opt/netrw/autoload/netrw.vim line 1822
  • Vulnerability type: CWE-78 — OS Command Injection

Root Cause

In the sftp reading path, tmpfile (derived from the remote URL's filename suffix) is passed to the sftp command unescaped:

" runtime/pack/dist/opt/netrw/autoload/netrw.vim line 1822 (macvim r183)
call netrw#os#Execute(s:netrw_silentxfer."!".g:netrw_sftp_cmd." ".netrw#os#Escape(g:netrw_machine.":".b:netrw_fname,1)." ".tmpfile)

tmpfile is constructed from the remote filename suffix (e.g., the extension part of sftp://host/foo.txt;id). When tmpfile contains shell metacharacters like ;, &&, or |, they are executed by the shell.

Attack Scenario
  1. Attacker tricks victim into opening sftp://attacker.com/payload;touch /tmp/pwned
  2. MacVim's netrw constructs tmpfile containing ;touch /tmp/pwned
  3. The sftp command executes with the unescaped tmpfile suffix, running the injected command

Verification

$ grep -n 'netrw_sftp_cmd.*tmpfile' runtime/pack/dist/opt/netrw/autoload/netrw.vim
1822:      call netrw#os#Execute(s:netrw_silentxfer."!".g:netrw_sftp_cmd." ".netrw#os#Escape(...)..." ".tmpfile)

The fix netrw#os#Escape(tmpfile,1) is absent. Patch 9.2.0383 not present:

$ git log --all --oneline | grep -i '9.2.0383\|sftp\|85ch'
(no output)

Suggested Fix

Merge vim patches up to at least 9.2.0383. The fix escapes tmpfile:

" Fixed (vim 9.2.0383):
call netrw#os#Execute(s:netrw_silentxfer."!".g:netrw_sftp_cmd." ".netrw#os#Escape(g:netrw_machine.":".b:netrw_fname,1)." ".netrw#os#Escape(tmpfile,1))

References

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

Start with runtime/pack/dist/opt/netrw/autoload/netrw.vim at line 1822 and compare it with Vim fix 405e2fb6 from version 9.2.0383. Verify the affected sftp:// and file: URL path using the grep command shown in the issue; done means tmpfile is escaped and the upstream fix is present.

Written by the indexing model from the issue text.

Assessment

Tech stack
macos, vim
Domain
desktop, security
Issue type
Bug
Difficulty
2/5
Estimated time
1-3 hours
Activity status
Quiet
Clarity
Clearly specified
Newbie friendliness
76/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.