Vim disclosed a medium-severity command injection flaw in its tar.vim plugin, tracked as CVE-2026-46483 and GHSA-2fpv-9ff7-xg5w, affecting versions earlier than 9.2.479. The bug is in tar#Vimuntar() in runtime/autoload/tar.vim, where .tgz archive filenames are passed to shell commands such as gunzip and gzip -d using shellescape() without the required special handling, allowing Vim command-line special-character expansion on Unix-like systems.
A successful attack can execute arbitrary shell commands with the privileges of the user running Vim if a victim has the tar plugin enabled, has a malicious archive on disk, and manually runs the non-routine :Vimuntar command. The issue was reported and analyzed by Aisle Research, disclosed by Christian Brabandt, and fixed in Vim patch v9.2.479.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
3 events from the most recent confirmed update back to the earliest known activity.
Christian Brabandt publicly disclosed the medium-severity vulnerability as CVE-2026-46483 and GHSA-2fpv-9ff7-xg5w. Advisory details explained that crafted .tgz filenames could trigger arbitrary shell command execution in the context of the Vim user.
Vim addressed the tar.vim command injection vulnerability in patch v9.2.479. Exploitation required a crafted archive filename, the tar plugin to be enabled, and a user to manually invoke the :Vimuntar command.
Aisle Research identified a command injection flaw in Vim's tar plugin affecting versions earlier than 9.2.479. The issue stems from tar#Vimuntar() using shellescape() without the special flag when handling .tgz archive filenames on Unix-like systems.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.