Summary
MacVim's src/findfile.c and src/optiondefs.h allow backtick expressions in the 'path' option to be executed when file completion is triggered. Since 'path' can be set via modelines, an attacker can embed a malicious backtick command in a project file that executes when the victim uses file-path completion. The fix from vim 9.2.0435 (190cb3c2) has not been applied to macvim r183.
Vulnerability Details
- GHSA: GHSA-hwg5-3cxw-wvvg
- CVE: CVE-2026-44656
- Upstream fix (vim): 9.2.0435 (commit
190cb3c2b6e53290735f2c5cab1a06f703a90e69, 2026-05-03)
- Affected code:
src/findfile.c + src/optiondefs.h ('path' option)
- Vulnerability type: CWE-78 — OS Command Injection
Root Cause
The 'path' option is not marked P_SECURE in src/optiondefs.h, so it can be set via modelines:
/* src/optiondefs.h line 2067 (macvim r183) */
{"path", "pa", P_STRING|P_EXPAND|P_VI_DEF|P_COMMA|P_NODUP,
Missing P_SECURE allows a modeline to set path+=\cmd`. In src/findfile.c, when file completion is performed for 'path'entries, backtick expressions are expanded via the shell — executingcmd`.
Attack Scenario
- Attacker places a project file with a modeline:
// vim: set path+=`id>/tmp/pwned` :
- Victim opens the file in MacVim with modeline support enabled (default)
- MacVim sets
path to include the backtick expression
- When the victim presses
Tab for :find completion, MacVim expands the backtick and executes id>/tmp/pwned
Verification
$ grep -n '"path".*P_STRING' src/optiondefs.h
2067: {"path", "pa", P_STRING|P_EXPAND|P_VI_DEF|P_COMMA|P_NODUP,
Missing P_SECURE. Also missing the backtick check in findfile.c. Patch 9.2.0435 not present:
$ git log --all --oneline | grep -i '9.2.0435\|path.*backtick\|hwg5'
(no output)
Suggested Fix
Merge vim patches up to at least 9.2.0435. The fix:
- Adds
P_SECURE to 'path' in optiondefs.h:
{"path", "pa", P_STRING|P_EXPAND|P_VI_DEF|P_SECURE|P_COMMA|P_NODUP,
- Adds a backtick guard in
findfile.c:
/* do not expand backticks, could have been set via a modeline */
if (vim_strchr(buf, '`') != NULL)
continue;
References
Summary
MacVim's
src/findfile.candsrc/optiondefs.hallow backtick expressions in the'path'option to be executed when file completion is triggered. Since'path'can be set via modelines, an attacker can embed a malicious backtick command in a project file that executes when the victim uses file-path completion. The fix from vim 9.2.0435 (190cb3c2) has not been applied to macvim r183.Vulnerability Details
190cb3c2b6e53290735f2c5cab1a06f703a90e69, 2026-05-03)src/findfile.c+src/optiondefs.h('path'option)Root Cause
The
'path'option is not markedP_SECUREinsrc/optiondefs.h, so it can be set via modelines:Missing
P_SECUREallows a modeline to setpath+=\cmd`. Insrc/findfile.c, when file completion is performed for'path'entries, backtick expressions are expanded via the shell — executingcmd`.Attack Scenario
// vim: set path+=`id>/tmp/pwned` :pathto include the backtick expressionTabfor:findcompletion, MacVim expands the backtick and executesid>/tmp/pwnedVerification
Missing
P_SECURE. Also missing the backtick check infindfile.c. Patch 9.2.0435 not present:Suggested Fix
Merge vim patches up to at least 9.2.0435. The fix:
P_SECUREto'path'inoptiondefs.h:{"path", "pa", P_STRING|P_EXPAND|P_VI_DEF|P_SECURE|P_COMMA|P_NODUP,findfile.c:References