ALPINE-CVE-2026-57453

Source
https://security.alpinelinux.org/vuln/CVE-2026-57453
Import Source
https://storage.googleapis.com/cve-osv-conversion/alpine/ALPINE-CVE-2026-57453.json
JSON Data
https://api.osv.dev/v1/vulns/ALPINE-CVE-2026-57453
Upstream
Published
2026-06-25T16:16:42.520Z
Modified
2026-08-19T00:30:03.046254864Z
Severity
  • 7.3 (High) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:L CVSS Calculator
Summary
[none]
Details

Vim is an open source, command line text editor. From 9.1.1784 until 9.2.0678, when the bundled zip plugin autoload/zip.vim falls back to PowerShell to browse, read, extract, update or delete entries in a zip archive, it builds the PowerShell command by inserting archive entry names that are quoted only for the shell, not for PowerShell. A crafted entry name can break out of the intended string context and cause PowerShell to execute arbitrary commands with the privileges of the user running Vim, triggered by opening, viewing or extracting the archive. This vulnerability is fixed in 9.2.0678.

References

Affected packages

Alpine:v3.23 / vim

Package

Name
vim
Purl
pkg:apk/alpine/vim?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
9.1.1784
Fixed
9.2.0854-r0

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/alpine/ALPINE-CVE-2026-57453.json"