macvim-dev / macvim-dev/macvim

[Security] MacVim affected by GHSA-hwg5-3cxw-wvvg — OS command injection via backticks in 'path' option completion (vim < 9.2.0435)

Open
#1,659 0 comments 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

Dominant language
Vim Script
Stars
7.9k
Forks
691
PR merge metrics
No merged PRs in 30d

Description

Summary

MacVim's src/findfile.c and src/optiondefs.h allow backtick expressions in the 'path' option to be executed when file completion is triggered. Since 'path' can be set via modelines, an attacker can embed a malicious backtick command in a project file that executes when the victim uses file-path completion. The fix from vim 9.2.0435 (190cb3c2) has not been applied to macvim r183.

Vulnerability Details

  • GHSA: GHSA-hwg5-3cxw-wvvg
  • CVE: CVE-2026-44656
  • Upstream fix (vim): 9.2.0435 (commit 190cb3c2b6e53290735f2c5cab1a06f703a90e69, 2026-05-03)
  • Affected code: src/findfile.c + src/optiondefs.h ('path' option)
  • Vulnerability type: CWE-78 — OS Command Injection

Root Cause

The 'path' option is not marked P_SECURE in src/optiondefs.h, so it can be set via modelines:

/* src/optiondefs.h line 2067 (macvim r183) */
{"path",    "pa",   P_STRING|P_EXPAND|P_VI_DEF|P_COMMA|P_NODUP,

Missing P_SECURE allows a modeline to set path+=\cmd`. In src/findfile.c, when file completion is performed for 'path'entries, backtick expressions are expanded via the shell — executingcmd`.

Attack Scenario
  1. Attacker places a project file with a modeline:
    // vim: set path+=`id>/tmp/pwned` :
    
  2. Victim opens the file in MacVim with modeline support enabled (default)
  3. MacVim sets path to include the backtick expression
  4. When the victim presses Tab for :find completion, MacVim expands the backtick and executes id>/tmp/pwned

Verification

$ grep -n '"path".*P_STRING' src/optiondefs.h
2067:    {"path",    "pa",   P_STRING|P_EXPAND|P_VI_DEF|P_COMMA|P_NODUP,

Missing P_SECURE. Also missing the backtick check in findfile.c. Patch 9.2.0435 not present:

$ git log --all --oneline | grep -i '9.2.0435\|path.*backtick\|hwg5'
(no output)

Suggested Fix

Merge vim patches up to at least 9.2.0435. The fix:

  1. Adds P_SECURE to 'path' in optiondefs.h:
    {"path",    "pa",   P_STRING|P_EXPAND|P_VI_DEF|P_SECURE|P_COMMA|P_NODUP,
    
  2. Adds a backtick guard in findfile.c:
    /* do not expand backticks, could have been set via a modeline */
    if (vim_strchr(buf, '`') != NULL)
        continue;
    

References

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

Start with src/optiondefs.h and src/findfile.c, then compare the missing changes with Vim commit 190cb3c2 or version 9.2.0435. Verify the 'path' option and backtick handling match the upstream fix, and use the issue's grep checks and attack scenario to confirm the vulnerability is addressed.

Written by the indexing model from the issue text.

Assessment

Tech stack
c, macos, vim
Domain
desktop, security
Issue type
Bug
Difficulty
3/5
Estimated time
1-2 days
Activity status
Quiet
Clarity
Clearly specified
Newbie friendliness
68/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.