macvim-dev / macvim-dev/macvim

[Security] MacVim affected by GHSA-cwgx-gcj7-6qh8 — command injection via backtick expansion in tag filenames (vim < 9.2.0357)

Aperta Adatta ai principianti
#1,658 0 commenti 0 reazioni 0 assegnatari Vedi su GitHub

Nessuno ha ancora preso questa issue.

Lingua principale
Vim Script
Stelle
7.9k
Fork
691
Metriche di merge delle PR
Nessuna PR unita negli ultimi 30g

Descrizione

Summary

MacVim's src/tag.c expands backtick expressions in tag file tagname fields when processing wildcard patterns. A malicious tags file containing a backtick expression like `touch /tmp/pwned` as a filename causes arbitrary shell command execution when a user issues a :tag command. The fix from vim 9.2.0357 (c78194e4) has not been applied to macvim r183.

Vulnerability Details

  • GHSA: GHSA-cwgx-gcj7-6qh8
  • CVE: CVE-2026-41411
  • Upstream fix (vim): 9.2.0357 (commit c78194e4ee65bab5fef3b4f8de8f4e6ee47fbaa6, 2026-04-15)
  • Affected code: src/tag.c line 4141
  • Vulnerability type: CWE-78 — OS Command Injection

Root Cause

In src/tag.c, when a tag filename matches as a wildcard pattern, the filename is expanded — which includes backtick expansion (shell command substitution):

/* src/tag.c line 4141 (macvim r183) */
if (expand && mch_has_wildcard(fname))

Since backtick expressions (e.g., `cmd`) satisfy mch_has_wildcard(), they are expanded via the shell. A malicious tags file containing:

main	`touch /tmp/pwned`	/^int main/;"	f

causes touch /tmp/pwned to execute when the user runs :tag main.

Attack Scenario
  1. Attacker provides a malicious tags file in the project (e.g., via repository or build system)
  2. Victim opens a file in MacVim with set tags=Xtags pointing to the malicious file
  3. Victim issues :tag main or another tag navigation command
  4. MacVim expands the backtick expression and executes arbitrary shell commands

Verification

$ grep -n 'mch_has_wildcard.*fname' src/tag.c
4141:    if (expand && mch_has_wildcard(fname))

Missing the guard && vim_strchr(fname, '\') == NULL`. Patch 9.2.0357 not present:

$ git log --all --oneline | grep -i '9.2.0357\|backtick.*tag\|cwgx'
(no output)

Suggested Fix

Merge vim patches up to at least 9.2.0357. The fix adds a backtick exclusion:

/* Fixed (vim 9.2.0357): disallow backticks, they could execute arbitrary shell commands */
if (expand && mch_has_wildcard(fname) && vim_strchr(fname, '`') == NULL)

References

Guida per i contributori

Apri la guida per i contributori

Come iniziare

  1. Leggi tutta la issue e poi la guida ai contributi del progetto.
  2. Commenta sulla issue per dire che te ne occupi tu — evita che due persone facciano lo stesso lavoro.
  3. Fai un fork del repository e lavora su un branch.
  4. Apri una pull request che faccia riferimento al numero della issue.

Direzione di ricerca

Leggi src/tag.c intorno alla riga 4141 e confrontalo con il commit c78194e4 di Vim 9.2.0357. Verifica che la gestione dei tag non espanda più i nomi di file contenenti backtick, preservando al contempo la normale navigazione dei tag con wildcard; l’issue non fornisce alcun test di regressione denominato, quindi esamina i test dei tag esistenti per la validazione.

Scritto dal modello di indicizzazione a partire dal testo della issue.

Valutazione

Stack tecnologico
c, macos, vim
Ambito
desktop, security
Tipo di issue
Bug
Difficoltà
2/5
Tempo stimato
1-3 ore
Stato di attività
Tranquilla
Chiarezza
Specificata chiaramente
Idoneità per principianti
76/100

Ricevi le nuove issue nella tua casella

Un breve riepilogo di issue GitHub adatte ai principianti.