Vim is an open source, command line text editor. Prior to 9.2.0845, StructMembers() in runtime/autoload/ccomplete.vim constructs and executes a vimgrep command using an insufficiently escaped typeref: or typename: value from a tags file, allowing an unterminated collection followed by a command separator to execute arbitrary Ex and operating-system commands when a user invokes C omni-completion with CTRL-X CTRL-O on a member access whose type is resolved from that tags file. This issue is fixed in version 9.2.0845.
{
"cna_assigner": "GitHub_M",
"cwe_ids": [
"CWE-829",
"CWE-94"
],
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/73xxx/CVE-2026-73073.json"
}"2026-08-20T09:52:36Z"
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-73073.json"
[
{
"deprecated": false,
"target": {
"file": "src/version.c"
},
"signature_type": "Line",
"source": "https://github.com/vim/vim/commit/2f628d8104958fa7421664f792ca6d4f7a39a10f",
"digest": {
"line_hashes": [
"146200493773228420153804765641940418619",
"208546909364565683421784034073854961742",
"215410264845009213883922768393120765621",
"136591886004636278246290028029818810708"
],
"threshold": 0.9
},
"signature_version": "v1",
"id": "CVE-2026-73073-5447d98b"
}
]