[Security] MacVim affected by GHSA-85ch-p2qr-m5gx — netrw OS command injection via sftp:/file: URL tempfile suffix (vim < 9.2.0383)
Nobody has claimed this yet.
Assessment
- Difficulty
- 2/5
- Estimated time
- 1-3 hours
- Newbie friendliness
- 76/100
Research direction
Start with runtime/pack/dist/opt/netrw/autoload/netrw.vim at line 1822 and compare it with Vim fix 405e2fb6 from version 9.2.0383. Verify the affected sftp:// and file: URL path using the grep command shown in the issue; done means tmpfile is escaped and the upstream fix is present.
Written by the indexing model from the issue text.
Description
Summary
MacVim bundles the netrw plugin (runtime/pack/dist/opt/netrw/autoload/netrw.vim) which passes an unescaped tmpfile variable to a shell command when fetching remote files via sftp:// or file: URLs. A crafted URL with a shell metacharacter in the filename suffix causes arbitrary command execution. The fix from vim 9.2.0383 (405e2fb6) has not been applied to macvim r183.
Vulnerability Details
- GHSA: GHSA-85ch-p2qr-m5gx
- CVE: CVE-2026-42307
- Upstream fix (vim): 9.2.0383 (commit
405e2fb6c2e35e09cb64e0f92c1efdafd6b3978a, 2026-04-21) - Affected code:
runtime/pack/dist/opt/netrw/autoload/netrw.vimline 1822 - Vulnerability type: CWE-78 — OS Command Injection
Root Cause
In the sftp reading path, tmpfile (derived from the remote URL's filename suffix) is passed to the sftp command unescaped:
" runtime/pack/dist/opt/netrw/autoload/netrw.vim line 1822 (macvim r183)
call netrw#os#Execute(s:netrw_silentxfer."!".g:netrw_sftp_cmd." ".netrw#os#Escape(g:netrw_machine.":".b:netrw_fname,1)." ".tmpfile)
tmpfile is constructed from the remote filename suffix (e.g., the extension part of sftp://host/foo.txt;id). When tmpfile contains shell metacharacters like ;, &&, or |, they are executed by the shell.
Attack Scenario
- Attacker tricks victim into opening
sftp://attacker.com/payload;touch /tmp/pwned - MacVim's netrw constructs
tmpfilecontaining;touch /tmp/pwned - The sftp command executes with the unescaped
tmpfilesuffix, running the injected command
Verification
$ grep -n 'netrw_sftp_cmd.*tmpfile' runtime/pack/dist/opt/netrw/autoload/netrw.vim
1822: call netrw#os#Execute(s:netrw_silentxfer."!".g:netrw_sftp_cmd." ".netrw#os#Escape(...)..." ".tmpfile)
The fix netrw#os#Escape(tmpfile,1) is absent. Patch 9.2.0383 not present:
$ git log --all --oneline | grep -i '9.2.0383\|sftp\|85ch'
(no output)
Suggested Fix
Merge vim patches up to at least 9.2.0383. The fix escapes tmpfile:
" Fixed (vim 9.2.0383):
call netrw#os#Execute(s:netrw_silentxfer."!".g:netrw_sftp_cmd." ".netrw#os#Escape(g:netrw_machine.":".b:netrw_fname,1)." ".netrw#os#Escape(tmpfile,1))
References
- Dominant language
- Vim Script
- Stars
- 7.9k
- Forks
- 691
- PR merge metrics
- No merged PRs in 30d
Contributor guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
More from macvim-dev/macvim
-
Difficulty 2/5 1-3 hours Newbie friendliness 68/100
macvim-dev/macvim#1697 · 4 comments ·
-
Difficulty 2/5 1-3 hours Newbie friendliness 76/100
macvim-dev/macvim#1658 ·
-
Difficulty 2/5 1-3 hours Newbie friendliness 76/100
macvim-dev/macvim#1655 ·
-
Difficulty 2/5 Half a day Newbie friendliness 72/100
macvim-dev/macvim#1653 ·
-
Difficulty 4/5 3-5 days Newbie friendliness 48/100
macvim-dev/macvim#1696 · 1 comment ·
All issues in macvim-dev/macvim
Similar issues
-
Difficulty 2/5 1-3 hours Newbie friendliness 84/100
Eynzof/Hermes-CN-Desktop#610 ·
-
Help-Wanted Package-Request
Difficulty 2/5 1-3 hours Newbie friendliness 68/100
microsoft/winget-pkgs#438682 ·
-
Difficulty 2/5 1-3 hours Newbie friendliness 78/100
Automattic/studio#4908 ·
-
bug
Difficulty 2/5 1-3 hours Newbie friendliness 68/100
-
os:macos
Difficulty 2/5 1-3 hours Newbie friendliness 78/100