macvim-dev / macvim-dev/macvim

[Security] MacVim affected by GHSA-hwg5-3cxw-wvvg — OS command injection via backticks in 'path' option completion (vim < 9.2.0435)

Offen
#1,659 0 Kommentare 0 Reaktionen 0 zugewiesene Personen Auf GitHub ansehen

Dieses Issue hat noch niemand übernommen.

Vorherrschende Sprache
Vim Script
Sterne
7.9k
Forks
691
PR-Merge-Kennzahlen
Keine gemergten PRs in 30 T.

Beschreibung

Summary

MacVim's src/findfile.c and src/optiondefs.h allow backtick expressions in the 'path' option to be executed when file completion is triggered. Since 'path' can be set via modelines, an attacker can embed a malicious backtick command in a project file that executes when the victim uses file-path completion. The fix from vim 9.2.0435 (190cb3c2) has not been applied to macvim r183.

Vulnerability Details

  • GHSA: GHSA-hwg5-3cxw-wvvg
  • CVE: CVE-2026-44656
  • Upstream fix (vim): 9.2.0435 (commit 190cb3c2b6e53290735f2c5cab1a06f703a90e69, 2026-05-03)
  • Affected code: src/findfile.c + src/optiondefs.h ('path' option)
  • Vulnerability type: CWE-78 — OS Command Injection

Root Cause

The 'path' option is not marked P_SECURE in src/optiondefs.h, so it can be set via modelines:

/* src/optiondefs.h line 2067 (macvim r183) */
{"path",    "pa",   P_STRING|P_EXPAND|P_VI_DEF|P_COMMA|P_NODUP,

Missing P_SECURE allows a modeline to set path+=\cmd`. In src/findfile.c, when file completion is performed for 'path'entries, backtick expressions are expanded via the shell — executingcmd`.

Attack Scenario
  1. Attacker places a project file with a modeline:
    // vim: set path+=`id>/tmp/pwned` :
    
  2. Victim opens the file in MacVim with modeline support enabled (default)
  3. MacVim sets path to include the backtick expression
  4. When the victim presses Tab for :find completion, MacVim expands the backtick and executes id>/tmp/pwned

Verification

$ grep -n '"path".*P_STRING' src/optiondefs.h
2067:    {"path",    "pa",   P_STRING|P_EXPAND|P_VI_DEF|P_COMMA|P_NODUP,

Missing P_SECURE. Also missing the backtick check in findfile.c. Patch 9.2.0435 not present:

$ git log --all --oneline | grep -i '9.2.0435\|path.*backtick\|hwg5'
(no output)

Suggested Fix

Merge vim patches up to at least 9.2.0435. The fix:

  1. Adds P_SECURE to 'path' in optiondefs.h:
    {"path",    "pa",   P_STRING|P_EXPAND|P_VI_DEF|P_SECURE|P_COMMA|P_NODUP,
    
  2. Adds a backtick guard in findfile.c:
    /* do not expand backticks, could have been set via a modeline */
    if (vim_strchr(buf, '`') != NULL)
        continue;
    

References

Beitragsleitfaden

Beitragsleitfaden öffnen

Erste Schritte

  1. Lies das ganze Issue und danach den Beitragsleitfaden des Projekts.
  2. Schreib ins Issue, dass du es übernimmst — das erspart doppelte Arbeit.
  3. Forke das Repository und arbeite in einem Branch.
  4. Öffne einen Pull Request, der die Issue-Nummer nennt.

Rechercherichtung

Beginnen Sie mit src/optiondefs.h und src/findfile.c und vergleichen Sie anschließend die fehlenden Änderungen mit dem Vim-Commit 190cb3c2 oder der Version 9.2.0435. Überprüfen Sie, ob die Option 'path' und die Behandlung von Backticks mit dem Upstream-Fix übereinstimmen, und verwenden Sie die grep-Prüfungen und das Angriffsszenario des Issues, um zu bestätigen, dass die Sicherheitslücke behoben ist.

Vom Indexierungsmodell aus dem Issue-Text verfasst.

Bewertung

Tech-Stack
c, macos, vim
Bereich
desktop, security
Issue-Typ
Bug
Schwierigkeit
3/5
Geschätzter Aufwand
1-2 Tage
Aktivitätsstatus
Ruhig
Klarheit
Klar beschrieben
Anfängerfreundlichkeit
68/100

Neue Issues direkt in Ihr Postfach

Eine kurze Übersicht über anfängerfreundliche GitHub-Issues.