A security issue was reported in Vim on 02 May 2026. It affects Vim versions before 9.2.0435 and is currently rated Medium. A CVE has been requested but was not assigned at the time of the report. The weakness is classified as CWE-78: OS Command Injection. The issue exists in Vim’s command-line completion for
Code: Select all
:findCode: Select all
'path'Code: Select all
'path'Code: Select all
:findCode: Select all
:sfindCode: Select all
:tabfind