CVE-2026-44656 is an OS command injection vulnerability in Vim versions before 9.2.0435. Vim's :find command-line completion executes backtick-enclosed shell commands embedded in the path option. Because this option lacks the P_SECURE flag, an attacker-controlled file can set it through a modeline. Opening the file and subsequently triggering :find completion can execute attacker-supplied shell commands. Vim 9.2.0435 fixes the vulnerability.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository is a real local/file-based exploit reproduction environment for CVE-2026-44656, a Vim modeline command injection issue. The exploit abuses backtick expansion inside the 'path' option set from a file modeline. When a user opens the crafted file and invokes ':find' completion with Tab, Vim evaluates the backtick expression and executes an attacker-controlled command. Repository structure is simple despite bundling a large upstream Vim source tree. The meaningful exploit components are: (1) 'poc.txt', which contains the malicious modeline `// vim: set path=.,`./eval.sh` :`; (2) 'eval.sh', a shell payload that runs `touch ./sakana.pwn`; (3) 'Dockerfile', which builds a Debian-based container, compiles the included vulnerable Vim source, and stages the PoC files; and (4) README files documenting reproduction. The 'vim/' directory is mostly upstream Vim source/runtime content used to build the vulnerable target, not custom exploit logic. Main exploit capability: arbitrary command execution as the local Vim user. There are no C2, remote callbacks, or network targets in the exploit itself. The trigger is user interaction with a malicious file plus Tab completion in ':find'. The payload is basic and hardcoded, so maturity is OPERATIONAL rather than weaponized. The exploit is not merely a detector; it demonstrates code execution by creating a local marker file.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
8 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A locally exploitable vulnerability requiring no privileges but requiring user interaction. The supplied CVSS vectors indicate low confidentiality and integrity impacts; availability impact differs between CVSS versions. The content reports available exploits and a patch published May 13, 2026, but does not identify the affected product or underlying flaw.
A moderate-severity local vulnerability addressed by a Rocky Linux 9.6 TuxCare live-security advisory. The listed CVSS v3.0 vector requires local access and user interaction, with low confidentiality, integrity, and availability impact.
A vulnerability referenced in a Huawei EulerOS security advisory affecting EulerOS UVP 2.13.0 vim-related packages; specific flaw details are not provided in the content.
A vulnerability listed as a referenced CVE in the EulerOS SA-2026-3204 advisory.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.