macvim-dev / macvim-dev/macvim

[Security] MacVim affected by GHSA-hwg5-3cxw-wvvg — OS command injection via backticks in 'path' option completion (vim < 9.2.0435)

Aperta
#1,659 0 commenti 0 reazioni 0 assegnatari Vedi su GitHub

Nessuno ha ancora preso questa issue.

Lingua principale
Vim Script
Stelle
7.9k
Fork
691
Metriche di merge delle PR
Nessuna PR unita negli ultimi 30g

Descrizione

Summary

MacVim's src/findfile.c and src/optiondefs.h allow backtick expressions in the 'path' option to be executed when file completion is triggered. Since 'path' can be set via modelines, an attacker can embed a malicious backtick command in a project file that executes when the victim uses file-path completion. The fix from vim 9.2.0435 (190cb3c2) has not been applied to macvim r183.

Vulnerability Details

  • GHSA: GHSA-hwg5-3cxw-wvvg
  • CVE: CVE-2026-44656
  • Upstream fix (vim): 9.2.0435 (commit 190cb3c2b6e53290735f2c5cab1a06f703a90e69, 2026-05-03)
  • Affected code: src/findfile.c + src/optiondefs.h ('path' option)
  • Vulnerability type: CWE-78 — OS Command Injection

Root Cause

The 'path' option is not marked P_SECURE in src/optiondefs.h, so it can be set via modelines:

/* src/optiondefs.h line 2067 (macvim r183) */
{"path",    "pa",   P_STRING|P_EXPAND|P_VI_DEF|P_COMMA|P_NODUP,

Missing P_SECURE allows a modeline to set path+=\cmd`. In src/findfile.c, when file completion is performed for 'path'entries, backtick expressions are expanded via the shell — executingcmd`.

Attack Scenario
  1. Attacker places a project file with a modeline:
    // vim: set path+=`id>/tmp/pwned` :
    
  2. Victim opens the file in MacVim with modeline support enabled (default)
  3. MacVim sets path to include the backtick expression
  4. When the victim presses Tab for :find completion, MacVim expands the backtick and executes id>/tmp/pwned

Verification

$ grep -n '"path".*P_STRING' src/optiondefs.h
2067:    {"path",    "pa",   P_STRING|P_EXPAND|P_VI_DEF|P_COMMA|P_NODUP,

Missing P_SECURE. Also missing the backtick check in findfile.c. Patch 9.2.0435 not present:

$ git log --all --oneline | grep -i '9.2.0435\|path.*backtick\|hwg5'
(no output)

Suggested Fix

Merge vim patches up to at least 9.2.0435. The fix:

  1. Adds P_SECURE to 'path' in optiondefs.h:
    {"path",    "pa",   P_STRING|P_EXPAND|P_VI_DEF|P_SECURE|P_COMMA|P_NODUP,
    
  2. Adds a backtick guard in findfile.c:
    /* do not expand backticks, could have been set via a modeline */
    if (vim_strchr(buf, '`') != NULL)
        continue;
    

References

Guida per i contributori

Apri la guida per i contributori

Come iniziare

  1. Leggi tutta la issue e poi la guida ai contributi del progetto.
  2. Commenta sulla issue per dire che te ne occupi tu — evita che due persone facciano lo stesso lavoro.
  3. Fai un fork del repository e lavora su un branch.
  4. Apri una pull request che faccia riferimento al numero della issue.

Direzione di ricerca

Inizia con src/optiondefs.h e src/findfile.c, quindi confronta le modifiche mancanti con il commit di Vim 190cb3c2 o la versione 9.2.0435. Verifica che l'opzione 'path' e la gestione dei backtick corrispondano alla correzione upstream e usa i controlli grep e lo scenario di attacco dell'issue per confermare che la vulnerabilità sia stata risolta.

Scritto dal modello di indicizzazione a partire dal testo della issue.

Valutazione

Stack tecnologico
c, macos, vim
Ambito
desktop, security
Tipo di issue
Bug
Difficoltà
3/5
Tempo stimato
1-2 giorni
Stato di attività
Tranquilla
Chiarezza
Specificata chiaramente
Idoneità per principianti
68/100

Ricevi le nuove issue nella tua casella

Un breve riepilogo di issue GitHub adatte ai principianti.