CVE-2026-39881
ADVISORY - nistSummary
Vim is an open source, command line text editor. Prior to 9.2.0316, a command injection vulnerability in Vim's netbeans interface allows a malicious netbeans server to execute arbitrary Ex commands when Vim connects to it, via unsanitized strings in the defineAnnoType and specialKeys protocol messages. This vulnerability is fixed in 9.2.0316.
EPSS Score: 0.00009 (0.009)
Common Weakness Enumeration (CWE)
ADVISORY - nist
Improper Control of Generation of Code ('Code Injection')
ADVISORY - redhat
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
NIST
CREATED
UPDATED
ADVISORY IDCVE-2026-39881
EXPLOITABILITY SCORE
0.8
EXPLOITS FOUND
-
COMMON WEAKNESS ENUMERATION (CWE)
CVSS SCORE
5mediumAlpine
CREATED
UPDATED
ADVISORY IDCVE-2026-39881
EXPLOITABILITY SCORE
-
EXPLOITS FOUND
-
COMMON WEAKNESS ENUMERATION (CWE)-
Debian
CREATED
UPDATED
ADVISORY IDCVE-2026-39881
EXPLOITABILITY SCORE
-
EXPLOITS FOUND
-
COMMON WEAKNESS ENUMERATION (CWE)-
Ubuntu
CREATED
UPDATED
ADVISORY IDCVE-2026-39881
EXPLOITABILITY SCORE
1.8
EXPLOITS FOUND
-
COMMON WEAKNESS ENUMERATION (CWE)-
CVSS SCORE
7.8mediumRed Hat
CREATED
UPDATED
ADVISORY IDCVE-2026-39881
EXPLOITABILITY SCORE
0.8
EXPLOITS FOUND
-
COMMON WEAKNESS ENUMERATION (CWE)