macvim-dev / macvim-dev/macvim
[Security] MacVim affected by GHSA-hwg5-3cxw-wvvg — OS command injection via backticks in 'path' option completion (vim < 9.2.0435)
Nobody has claimed this yet.
- Dominant language
- Vim Script
- Stars
- 7.9k
- Forks
- 691
- PR merge metrics
- No merged PRs in 30d
Description
Summary
MacVim's src/findfile.c and src/optiondefs.h allow backtick expressions in the 'path' option to be executed when file completion is triggered. Since 'path' can be set via modelines, an attacker can embed a malicious backtick command in a project file that executes when the victim uses file-path completion. The fix from vim 9.2.0435 (190cb3c2) has not been applied to macvim r183.
Vulnerability Details
- GHSA: GHSA-hwg5-3cxw-wvvg
- CVE: CVE-2026-44656
- Upstream fix (vim): 9.2.0435 (commit
190cb3c2b6e53290735f2c5cab1a06f703a90e69, 2026-05-03) - Affected code:
src/findfile.c+src/optiondefs.h('path'option) - Vulnerability type: CWE-78 — OS Command Injection
Root Cause
The 'path' option is not marked P_SECURE in src/optiondefs.h, so it can be set via modelines:
/* src/optiondefs.h line 2067 (macvim r183) */
{"path", "pa", P_STRING|P_EXPAND|P_VI_DEF|P_COMMA|P_NODUP,
Missing P_SECURE allows a modeline to set path+=\cmd`. In src/findfile.c, when file completion is performed for 'path'entries, backtick expressions are expanded via the shell — executingcmd`.
Attack Scenario
- Attacker places a project file with a modeline:
// vim: set path+=`id>/tmp/pwned` : - Victim opens the file in MacVim with modeline support enabled (default)
- MacVim sets
pathto include the backtick expression - When the victim presses
Tabfor:findcompletion, MacVim expands the backtick and executesid>/tmp/pwned
Verification
$ grep -n '"path".*P_STRING' src/optiondefs.h
2067: {"path", "pa", P_STRING|P_EXPAND|P_VI_DEF|P_COMMA|P_NODUP,
Missing P_SECURE. Also missing the backtick check in findfile.c. Patch 9.2.0435 not present:
$ git log --all --oneline | grep -i '9.2.0435\|path.*backtick\|hwg5'
(no output)
Suggested Fix
Merge vim patches up to at least 9.2.0435. The fix:
- Adds
P_SECUREto'path'inoptiondefs.h:{"path", "pa", P_STRING|P_EXPAND|P_VI_DEF|P_SECURE|P_COMMA|P_NODUP, - Adds a backtick guard in
findfile.c:/* do not expand backticks, could have been set via a modeline */ if (vim_strchr(buf, '`') != NULL) continue;
References
Contributor guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
Research direction
Start with src/optiondefs.h and src/findfile.c, then compare the missing changes with Vim commit 190cb3c2 or version 9.2.0435. Verify the 'path' option and backtick handling match the upstream fix, and use the issue's grep checks and attack scenario to confirm the vulnerability is addressed.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- c, macos, vim
- Domain
- desktop, security
- Issue type
- Bug
- Difficulty
- 3/5
- Estimated time
- 1-2 days
- Activity status
- Quiet
- Clarity
- Clearly specified
- Newbie friendliness
- 68/100