Code Injection in Vim - #VU135702
Published: June 29, 2026
Vim
Detailed vulnerability description
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to improper control of code generation in runtime/autoload/phpcomplete.vim when processing a crafted PHP file during omni-completion. A remote attacker can trick the victim into opening a crafted file and invoking omni-completion to execute arbitrary code.
User interaction is required to open a crafted PHP file and manually invoke omni-completion, and exploitation requires filetype plugins to be enabled.