macvim-dev / macvim-dev/macvim
[Security] MacVim affected by GHSA-cwgx-gcj7-6qh8 — command injection via backtick expansion in tag filenames (vim < 9.2.0357)
Nobody has claimed this yet.
- Dominant language
- Vim Script
- Stars
- 7.9k
- Forks
- 691
- PR merge metrics
- No merged PRs in 30d
Description
Summary
MacVim's src/tag.c expands backtick expressions in tag file tagname fields when processing wildcard patterns. A malicious tags file containing a backtick expression like `touch /tmp/pwned` as a filename causes arbitrary shell command execution when a user issues a :tag command. The fix from vim 9.2.0357 (c78194e4) has not been applied to macvim r183.
Vulnerability Details
- GHSA: GHSA-cwgx-gcj7-6qh8
- CVE: CVE-2026-41411
- Upstream fix (vim): 9.2.0357 (commit
c78194e4ee65bab5fef3b4f8de8f4e6ee47fbaa6, 2026-04-15) - Affected code:
src/tag.cline 4141 - Vulnerability type: CWE-78 — OS Command Injection
Root Cause
In src/tag.c, when a tag filename matches as a wildcard pattern, the filename is expanded — which includes backtick expansion (shell command substitution):
/* src/tag.c line 4141 (macvim r183) */
if (expand && mch_has_wildcard(fname))
Since backtick expressions (e.g., `cmd`) satisfy mch_has_wildcard(), they are expanded via the shell. A malicious tags file containing:
main `touch /tmp/pwned` /^int main/;" f
causes touch /tmp/pwned to execute when the user runs :tag main.
Attack Scenario
- Attacker provides a malicious
tagsfile in the project (e.g., via repository or build system) - Victim opens a file in MacVim with
set tags=Xtagspointing to the malicious file - Victim issues
:tag mainor another tag navigation command - MacVim expands the backtick expression and executes arbitrary shell commands
Verification
$ grep -n 'mch_has_wildcard.*fname' src/tag.c
4141: if (expand && mch_has_wildcard(fname))
Missing the guard && vim_strchr(fname, '\') == NULL`. Patch 9.2.0357 not present:
$ git log --all --oneline | grep -i '9.2.0357\|backtick.*tag\|cwgx'
(no output)
Suggested Fix
Merge vim patches up to at least 9.2.0357. The fix adds a backtick exclusion:
/* Fixed (vim 9.2.0357): disallow backticks, they could execute arbitrary shell commands */
if (expand && mch_has_wildcard(fname) && vim_strchr(fname, '`') == NULL)
References
Contributor guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
Research direction
Read src/tag.c around line 4141 and compare it with Vim 9.2.0357 commit c78194e4. Verify that tag handling no longer expands backtick-containing filenames while preserving ordinary wildcard tag navigation; the issue provides no named regression test, so inspect existing tag tests for validation.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- c, macos, vim
- Domain
- desktop, security
- Issue type
- Bug
- Difficulty
- 2/5
- Estimated time
- 1-3 hours
- Activity status
- Quiet
- Clarity
- Clearly specified
- Newbie friendliness
- 76/100