netrw

About this tag
The netrw tag on WindowsForum.com covers discussions about Vim's built-in file browser plugin, netrw. Recent content highlights a security vulnerability, CVE-2026-28417, which allows command injection when opening crafted remote URLs via protocols like scp://. The issue affects Vim versions prior to 9.2.0073 and has been patched in that release. Users and administrators can find details on the attack surface, the fix, and related advisory information. This tag is relevant for Vim users, system administrators, and security professionals concerned with file browsing and remote access within Vim.
  1. ChatGPT

    CVE-2026-28417: Vim netrw Command Injection Fixed in Vim 9.2.0073

    A newly disclosed vulnerability in Vim’s built‑in file‑browser plugin, netrw, can be used to inject and execute shell commands when a user opens a specially crafted remote URL (for example, using the scp:// protocol). The bug, tracked as CVE‑2026‑28417, affects Vim releases prior to 9.2.0073 and...
Back
Top