]> git.ipfire.org Git - thirdparty/vim.git/commitdiff
patch 9.2.0839: [security]: arbitrary code execution via keyword lookup v9.2.0839
authorYasuhiro Matsumoto <mattn.jp@gmail.com>
Thu, 23 Jul 2026 19:13:15 +0000 (19:13 +0000)
committerChristian Brabandt <cb@256bit.org>
Thu, 23 Jul 2026 19:33:24 +0000 (19:33 +0000)
Problem:  [security]: arbitrary code execution via keyword lookup in
          sh.vim, zsh.vim and ps1.vim filetype plugin
          (manus-use)
Solution: For powershell, quote the commands using single quotes, for
          sh/zsh pass the argument as a separate list item to term_start()/system()
          (Yasuhiro Matsumoto).

Github Security Advisory:
https://github.com/vim/vim/security/advisories/GHSA-r5v6-q6j8-8qw2

Signed-off-by: Yasuhiro Matsumoto <mattn.jp@gmail.com>
Signed-off-by: Christian Brabandt <cb@256bit.org>
runtime/ftplugin/ps1.vim
runtime/ftplugin/sh.vim
runtime/ftplugin/zsh.vim
src/version.c

index f1fe78df4c4126bd1403cef6c639b6748b7558cf..9ff764a282e65137820ffca85b320adc319ac088 100644 (file)
@@ -6,6 +6,7 @@
 "              2024 May 23 by Riley Bruins <ribru17@gmail.com> ('commentstring')
 "              2024 Sep 19 by Konfekt (simplify keywordprg #15696)
 "              2025 Jul 22 by phanium (use :hor term #17822)
+"              2026 Jul 10 by Vim Project (quote K argument, prevent command injection)
 
 " Only do this when not done yet for this buffer
 if exists("b:did_ftplugin") | finish | endif
@@ -52,9 +53,9 @@ endif
 
 if exists('s:pwsh_cmd')
   if exists(':terminal') == 2
-    command! -buffer -nargs=1 GetHelp silent exe 'hor term ' . s:pwsh_cmd . ' -NoLogo -NoProfile -NonInteractive -ExecutionPolicy RemoteSigned -Command Get-Help -Full "<args>"' . (executable('less') ? ' | less' : '')
+    command! -buffer -nargs=1 GetHelp call term_start([s:pwsh_cmd, '-NoLogo', '-NoProfile', '-NonInteractive', '-ExecutionPolicy', 'RemoteSigned', '-Command', "Get-Help -Full '" . substitute(<q-args>, "'", "''", 'g') . "'" . (executable('less') ? ' | less' : '')])
   else
-    command! -buffer -nargs=1 GetHelp echo system(s:pwsh_cmd . ' -NoLogo -NoProfile -NonInteractive -ExecutionPolicy RemoteSigned -Command Get-Help -Full <args>')
+    command! -buffer -nargs=1 GetHelp echo system([s:pwsh_cmd, '-NoLogo', '-NoProfile', '-NonInteractive', '-ExecutionPolicy', 'RemoteSigned', '-Command', "Get-Help -Full '" . substitute(<q-args>, "'", "''", 'g') . "'"])
   endif
   setlocal keywordprg=:GetHelp
   let b:undo_ftplugin ..= " | setl kp< | sil! delc -buffer GetHelp"
index 18cd219cdc0dbb4f38218e521e787faad395a4f5..45e6f44fcf046296cceb4f5acb53a396e92393b1 100644 (file)
@@ -8,6 +8,7 @@
 "                      2024 Dec 29 by Vim Project (improve setting shellcheck compiler)
 "                      2025 Mar 09 by Vim Project (set b:match_skip)
 "                      2025 Jul 22 by phanium (use :hor term #17822)
+"                      2026 Jul 10 by Vim Project (pass K argument as a list, prevent shell injection)
 
 if exists("b:did_ftplugin")
   finish
@@ -54,9 +55,9 @@ let s:is_kornshell = get(b:, "is_kornshell", get(g:, "is_kornshell", 0))
 
 if s:is_bash
   if exists(':terminal') == 2
-    command! -buffer -nargs=1 ShKeywordPrg silent exe ':hor term bash -c "help "<args>" 2>/dev/null || man "<args>""'
+    command! -buffer -nargs=1 ShKeywordPrg call term_start(['bash', '-c', 'help "$1" 2>/dev/null || man "$1"', '--', <q-args>])
   else
-    command! -buffer -nargs=1 ShKeywordPrg echo system('bash -c "help <args>" 2>/dev/null || MANPAGER= man "<args>"')
+    command! -buffer -nargs=1 ShKeywordPrg echo system(['bash', '-c', 'help "$1" 2>/dev/null || MANPAGER= man "$1"', '--', <q-args>])
   endif
   setlocal keywordprg=:ShKeywordPrg
   let b:undo_ftplugin ..= " | setl kp< | sil! delc -buffer ShKeywordPrg"
index 850bef055cc8ff0ffa296ddfca981caac7a3c3ee..8163585939638b6eb05dc2a5444b7a30d89b444f 100644 (file)
@@ -2,7 +2,7 @@
 " Language:             Zsh shell script
 " Maintainer:           Christian Brabandt <cb@256bit.org>
 " Previous Maintainer:  Nikolai Weibull <now@bitwi.se>
-" Latest Revision:      2025 Jul 23
+" Latest Revision:      2026 Jul 23
 " License:              Vim (see :h license)
 " Repository:           https://github.com/chrisbra/vim-zsh
 
@@ -25,9 +25,9 @@ endif
 
 if executable('zsh') && &shell !~# '/\%(nologin\|false\)$'
   if exists(':terminal') == 2
-    command! -buffer -nargs=1 ZshKeywordPrg silent exe ':hor :term zsh -c "autoload -Uz run-help; run-help <args>"'
-  else
-    command! -buffer -nargs=1 ZshKeywordPrg echo system('MANPAGER= zsh -c "autoload -Uz run-help; run-help <args> 2>/dev/null"')
+    command! -buffer -nargs=1 ZshKeywordPrg call term_start(['zsh', '-c', 'autoload -Uz run-help; run-help "$1"', '--', <q-args>])
+  elseif has("patch-9.2.0250")
+    command! -buffer -nargs=1 ZshKeywordPrg echo system(['zsh', '-c', 'autoload -Uz run-help; MANPAGER= run-help "$1" 2>/dev/null', '--', <q-args>])
   endif
   setlocal keywordprg=:ZshKeywordPrg
   let b:undo_ftplugin .= '| setl keywordprg< | sil! delc -buffer ZshKeywordPrg'
index 07772b03f5b807a0f2689c958037ebb8436ebe46..9d3c95b005b26fe8da0792a706d9d26c4accd098 100644 (file)
@@ -758,6 +758,8 @@ static char *(features[]) =
 
 static int included_patches[] =
 {   /* Add new patch number below this line */
+/**/
+    839,
 /**/
     838,
 /**/