From: Yasuhiro Matsumoto Date: Thu, 23 Jul 2026 19:13:15 +0000 (+0000) Subject: patch 9.2.0839: [security]: arbitrary code execution via keyword lookup X-Git-Tag: v9.2.0839^0 X-Git-Url: http://git.ipfire.org/gitweb/index.cgi?a=commitdiff_plain;h=c5a82fe013e73c98004ad7cd4f906b1ad1ed610e;p=thirdparty%2Fvim.git patch 9.2.0839: [security]: arbitrary code execution via keyword lookup Problem: [security]: arbitrary code execution via keyword lookup in sh.vim, zsh.vim and ps1.vim filetype plugin (manus-use) Solution: For powershell, quote the commands using single quotes, for sh/zsh pass the argument as a separate list item to term_start()/system() (Yasuhiro Matsumoto). Github Security Advisory: https://github.com/vim/vim/security/advisories/GHSA-r5v6-q6j8-8qw2 Signed-off-by: Yasuhiro Matsumoto Signed-off-by: Christian Brabandt --- diff --git a/runtime/ftplugin/ps1.vim b/runtime/ftplugin/ps1.vim index f1fe78df4c..9ff764a282 100644 --- a/runtime/ftplugin/ps1.vim +++ b/runtime/ftplugin/ps1.vim @@ -6,6 +6,7 @@ " 2024 May 23 by Riley Bruins ('commentstring') " 2024 Sep 19 by Konfekt (simplify keywordprg #15696) " 2025 Jul 22 by phanium (use :hor term #17822) +" 2026 Jul 10 by Vim Project (quote K argument, prevent command injection) " Only do this when not done yet for this buffer if exists("b:did_ftplugin") | finish | endif @@ -52,9 +53,9 @@ endif if exists('s:pwsh_cmd') if exists(':terminal') == 2 - command! -buffer -nargs=1 GetHelp silent exe 'hor term ' . s:pwsh_cmd . ' -NoLogo -NoProfile -NonInteractive -ExecutionPolicy RemoteSigned -Command Get-Help -Full ""' . (executable('less') ? ' | less' : '') + command! -buffer -nargs=1 GetHelp call term_start([s:pwsh_cmd, '-NoLogo', '-NoProfile', '-NonInteractive', '-ExecutionPolicy', 'RemoteSigned', '-Command', "Get-Help -Full '" . substitute(, "'", "''", 'g') . "'" . (executable('less') ? ' | less' : '')]) else - command! -buffer -nargs=1 GetHelp echo system(s:pwsh_cmd . ' -NoLogo -NoProfile -NonInteractive -ExecutionPolicy RemoteSigned -Command Get-Help -Full ') + command! -buffer -nargs=1 GetHelp echo system([s:pwsh_cmd, '-NoLogo', '-NoProfile', '-NonInteractive', '-ExecutionPolicy', 'RemoteSigned', '-Command', "Get-Help -Full '" . substitute(, "'", "''", 'g') . "'"]) endif setlocal keywordprg=:GetHelp let b:undo_ftplugin ..= " | setl kp< | sil! delc -buffer GetHelp" diff --git a/runtime/ftplugin/sh.vim b/runtime/ftplugin/sh.vim index 18cd219cdc..45e6f44fcf 100644 --- a/runtime/ftplugin/sh.vim +++ b/runtime/ftplugin/sh.vim @@ -8,6 +8,7 @@ " 2024 Dec 29 by Vim Project (improve setting shellcheck compiler) " 2025 Mar 09 by Vim Project (set b:match_skip) " 2025 Jul 22 by phanium (use :hor term #17822) +" 2026 Jul 10 by Vim Project (pass K argument as a list, prevent shell injection) if exists("b:did_ftplugin") finish @@ -54,9 +55,9 @@ let s:is_kornshell = get(b:, "is_kornshell", get(g:, "is_kornshell", 0)) if s:is_bash if exists(':terminal') == 2 - command! -buffer -nargs=1 ShKeywordPrg silent exe ':hor term bash -c "help "" 2>/dev/null || man """' + command! -buffer -nargs=1 ShKeywordPrg call term_start(['bash', '-c', 'help "$1" 2>/dev/null || man "$1"', '--', ]) else - command! -buffer -nargs=1 ShKeywordPrg echo system('bash -c "help " 2>/dev/null || MANPAGER= man ""') + command! -buffer -nargs=1 ShKeywordPrg echo system(['bash', '-c', 'help "$1" 2>/dev/null || MANPAGER= man "$1"', '--', ]) endif setlocal keywordprg=:ShKeywordPrg let b:undo_ftplugin ..= " | setl kp< | sil! delc -buffer ShKeywordPrg" diff --git a/runtime/ftplugin/zsh.vim b/runtime/ftplugin/zsh.vim index 850bef055c..8163585939 100644 --- a/runtime/ftplugin/zsh.vim +++ b/runtime/ftplugin/zsh.vim @@ -2,7 +2,7 @@ " Language: Zsh shell script " Maintainer: Christian Brabandt " Previous Maintainer: Nikolai Weibull -" Latest Revision: 2025 Jul 23 +" Latest Revision: 2026 Jul 23 " License: Vim (see :h license) " Repository: https://github.com/chrisbra/vim-zsh @@ -25,9 +25,9 @@ endif if executable('zsh') && &shell !~# '/\%(nologin\|false\)$' if exists(':terminal') == 2 - command! -buffer -nargs=1 ZshKeywordPrg silent exe ':hor :term zsh -c "autoload -Uz run-help; run-help "' - else - command! -buffer -nargs=1 ZshKeywordPrg echo system('MANPAGER= zsh -c "autoload -Uz run-help; run-help 2>/dev/null"') + command! -buffer -nargs=1 ZshKeywordPrg call term_start(['zsh', '-c', 'autoload -Uz run-help; run-help "$1"', '--', ]) + elseif has("patch-9.2.0250") + command! -buffer -nargs=1 ZshKeywordPrg echo system(['zsh', '-c', 'autoload -Uz run-help; MANPAGER= run-help "$1" 2>/dev/null', '--', ]) endif setlocal keywordprg=:ZshKeywordPrg let b:undo_ftplugin .= '| setl keywordprg< | sil! delc -buffer ZshKeywordPrg' diff --git a/src/version.c b/src/version.c index 07772b03f5..9d3c95b005 100644 --- a/src/version.c +++ b/src/version.c @@ -758,6 +758,8 @@ static char *(features[]) = static int included_patches[] = { /* Add new patch number below this line */ +/**/ + 839, /**/ 838, /**/