Summary
MacVim's src/tag.c expands backtick expressions in tag file tagname fields when processing wildcard patterns. A malicious tags file containing a backtick expression like `touch /tmp/pwned` as a filename causes arbitrary shell command execution when a user issues a :tag command. The fix from vim 9.2.0357 (c78194e4) has not been applied to macvim r183.
Vulnerability Details
- GHSA: GHSA-cwgx-gcj7-6qh8
- CVE: CVE-2026-41411
- Upstream fix (vim): 9.2.0357 (commit
c78194e4ee65bab5fef3b4f8de8f4e6ee47fbaa6, 2026-04-15)
- Affected code:
src/tag.c line 4141
- Vulnerability type: CWE-78 — OS Command Injection
Root Cause
In src/tag.c, when a tag filename matches as a wildcard pattern, the filename is expanded — which includes backtick expansion (shell command substitution):
/* src/tag.c line 4141 (macvim r183) */
if (expand && mch_has_wildcard(fname))
Since backtick expressions (e.g., `cmd`) satisfy mch_has_wildcard(), they are expanded via the shell. A malicious tags file containing:
main `touch /tmp/pwned` /^int main/;" f
causes touch /tmp/pwned to execute when the user runs :tag main.
Attack Scenario
- Attacker provides a malicious
tags file in the project (e.g., via repository or build system)
- Victim opens a file in MacVim with
set tags=Xtags pointing to the malicious file
- Victim issues
:tag main or another tag navigation command
- MacVim expands the backtick expression and executes arbitrary shell commands
Verification
$ grep -n 'mch_has_wildcard.*fname' src/tag.c
4141: if (expand && mch_has_wildcard(fname))
Missing the guard && vim_strchr(fname, '\') == NULL`. Patch 9.2.0357 not present:
$ git log --all --oneline | grep -i '9.2.0357\|backtick.*tag\|cwgx'
(no output)
Suggested Fix
Merge vim patches up to at least 9.2.0357. The fix adds a backtick exclusion:
/* Fixed (vim 9.2.0357): disallow backticks, they could execute arbitrary shell commands */
if (expand && mch_has_wildcard(fname) && vim_strchr(fname, '`') == NULL)
References
Summary
MacVim's
src/tag.cexpands backtick expressions in tag filetagnamefields when processing wildcard patterns. A malicious tags file containing a backtick expression like`touch /tmp/pwned`as a filename causes arbitrary shell command execution when a user issues a:tagcommand. The fix from vim 9.2.0357 (c78194e4) has not been applied to macvim r183.Vulnerability Details
c78194e4ee65bab5fef3b4f8de8f4e6ee47fbaa6, 2026-04-15)src/tag.cline 4141Root Cause
In
src/tag.c, when a tag filename matches as a wildcard pattern, the filename is expanded — which includes backtick expansion (shell command substitution):Since backtick expressions (e.g.,
`cmd`) satisfymch_has_wildcard(), they are expanded via the shell. A malicioustagsfile containing:causes
touch /tmp/pwnedto execute when the user runs:tag main.Attack Scenario
tagsfile in the project (e.g., via repository or build system)set tags=Xtagspointing to the malicious file:tag mainor another tag navigation commandVerification
Missing the guard
&& vim_strchr(fname, '\') == NULL`. Patch 9.2.0357 not present:Suggested Fix
Merge vim patches up to at least 9.2.0357. The fix adds a backtick exclusion:
References