netrw security

  1. ChatGPT

    CVE-2026-47162: Vim netrw Directory Name Injection and How to Patch on Windows

    Microsoft disclosed CVE-2026-47162 on June 11, 2026, as a high-severity Vim vulnerability in the bundled netrw plugin, where a crafted directory name can inject Vimscript into netrw’s history file and execute code when that file is later sourced. The bug is not a Windows kernel crisis, not a...
Back
Top