Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-57453— Vim: PowerShell Command Injection via Unescaped Filename in zip.vim Extraction

CVSS 6.5 · Medium EPSS 0.14% · P4

Possible ATT&CK Techniques 1AI

T1059.001 · PowerShell

Affected Version Matrix 1

VendorProductVersion RangeStatus
vimvim>= 9.1.1784, < 9.2.0678affected
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2026-57453

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Vim: PowerShell Command Injection via Unescaped Filename in zip.vim Extraction
Source: CVE Program / CVE List V5
Vulnerability Description
Vim is an open source, command line text editor. From 9.1.1784 until 9.2.0678, when the bundled zip plugin autoload/zip.vim falls back to PowerShell to browse, read, extract, update or delete entries in a zip archive, it builds the PowerShell command by inserting archive entry names that are quoted only for the shell, not for PowerShell. A crafted entry name can break out of the intended string context and cause PowerShell to execute arbitrary commands with the privileges of the user running Vim, triggered by opening, viewing or extracting the archive. This vulnerability is fixed in 9.2.0678.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:L
Source: CVE Program / CVE List V5
Vulnerability Type
在命令中使用的特殊元素转义处理不恰当(命令注入)
Source: CVE Program / CVE List V5
Vulnerability Title
Vim 命令注入漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Vim是Vim组织开源的一款跨平台的文本编辑器。 Vim 9.1.1784版本至9.2.0678之前版本存在命令注入漏洞,该漏洞源于构建PowerShell命令时未能正确引用存档条目名称,可能导致特制条目名称突破字符串环境并导致PowerShell执行任意命令。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
vimvim >= 9.1.1784, < 9.2.0678 -

II. Public POCs for CVE-2026-57453

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-57453

登录查看更多情报信息。

Patches & Fixes for CVE-2026-57453 (1)

Vendor Advisories for CVE-2026-57453 (1)

Vendor Pages for CVE-2026-57453 (1)

Same Patch Batch · vim · 2026-06-25 · 9 CVEs total

CVE-2026-574525.5 MEDIUMVim: Out-of-bounds Read with libsodium-encrypted Files
CVE-2026-558925.5 MEDIUMVim: Out-of-bounds Write in Spell File Prefix Dump
CVE-2026-574515.3 MEDIUMVim: Out-of-bounds Read in Text Property Count
CVE-2026-57456Vim: Arbitrary Code Execution via Python Omni-Completion Docstrings
CVE-2026-57455Vim: Stack out-of-bounds write in `spell_soundfold_sofo()` via an over-length `soundfold()
CVE-2026-57454Vim: Out-of-bounds Read with Text Properties
CVE-2026-55895Vim: Vimscript Code Injection in netrw NetrwLocalRmFile() via crafted filename
CVE-2026-55693Vim: Out-of-bounds Write in Spell File Word Count

IV. Related Vulnerabilities

V. Comments for CVE-2026-57453

No comments yet


Leave a comment