Summary
MacVim bundles runtime/autoload/tar.vim containing tar#Vimuntar(), which builds :!gunzip and :!gzip -d shell commands using shellescape(tartail) without the {special} flag. On Unix-like systems, Vim re-expands cmdline-special characters (%, #, !, etc.) before passing a :! command to the shell, so a crafted .tgz filename can inject arbitrary shell commands. The fix from vim 9.2.0479 (3fb5e58fbc63d86a3e65f1a141b0d67af2aa38a1) has not been applied to macvim r183.
Vulnerability Details
- GHSA: GHSA-2fpv-9ff7-xg5w
- CVE: CVE-2026-46483
- Upstream fix (vim): 9.2.0479 (commit
3fb5e58fbc63d86a3e65f1a141b0d67af2aa38a1, 2026-05-14)
- Affected code:
runtime/autoload/tar.vim — tar#Vimuntar() function
- Vulnerability type: CWE-78 — OS Command Injection
Root Cause
In tar#Vimuntar(), the archive tail filename (tartail = expand("%:t")) is passed to :! commands via shellescape() without the required second argument ({special}=1):
" runtime/autoload/tar.vim lines 809-812 (macvim r183)
if executable("gunzip")
silent exe "!gunzip ".shellescape(tartail)
elseif executable("gzip")
silent exe "!gzip -d ".shellescape(tartail)
As documented in :help shellescape(), when using the result in a :! command, the second argument must be non-zero so that Vim cmdline-special characters are also escaped. Without it, a filename like ';%$(touch pwned)'.tgz causes Vim to expand % and ! before the shell sees the argument.
Suggested Fix
Merge vim patches up to at least 9.2.0479. The fix adds , 1 to both shellescape() calls:
" Fixed (vim 9.2.0479):
if executable("gunzip")
silent exe "!gunzip ".shellescape(tartail, 1)
elseif executable("gzip")
silent exe "!gzip -d ".shellescape(tartail, 1)
References
Summary
MacVim bundles
runtime/autoload/tar.vimcontainingtar#Vimuntar(), which builds:!gunzipand:!gzip -dshell commands usingshellescape(tartail)without the{special}flag. On Unix-like systems, Vim re-expands cmdline-special characters (%,#,!, etc.) before passing a:!command to the shell, so a crafted.tgzfilename can inject arbitrary shell commands. The fix from vim 9.2.0479 (3fb5e58fbc63d86a3e65f1a141b0d67af2aa38a1) has not been applied to macvim r183.Vulnerability Details
3fb5e58fbc63d86a3e65f1a141b0d67af2aa38a1, 2026-05-14)runtime/autoload/tar.vim—tar#Vimuntar()functionRoot Cause
In
tar#Vimuntar(), the archive tail filename (tartail = expand("%:t")) is passed to:!commands viashellescape()without the required second argument ({special}=1):As documented in
:help shellescape(), when using the result in a:!command, the second argument must be non-zero so that Vim cmdline-special characters are also escaped. Without it, a filename like';%$(touch pwned)'.tgzcauses Vim to expand%and!before the shell sees the argument.Suggested Fix
Merge vim patches up to at least 9.2.0479. The fix adds
, 1to bothshellescape()calls:References