CVE-2026-59856: Vim: Arbitrary Code Execution via PHP Omni-Completion

Published Jul 9, 2026
·
Updated

Last updated 13 July 2026

Other sources

Vim is an open source, command line text editor. Prior to 9.2.0736, the PHP omni-completion script in runtime/autoload/phpcomplete.vim interpolates a class or trait name, taken from the contents of the edited buffer, into a search() pattern that is run via winexecute() without escaping. A name containing a single quote can terminate the search() string argument early, and because the bar is honored as an Ex command separator, the remainder of the name is run as Ex commands; via the :! command this allows arbitrary operating-system command execution when a victim opens a crafted PHP file and invokes omni-completion. This issue is fixed in version 9.2.0736.

MITRE

Vim: Arbitrary Code Execution via PHP Omni-Completion

Microsoft

Affected Software

4 affected componentsFixes available
vim Vim<9.2.0736
Microsoft azl3 vim 9.2.0735-1<9.2.0782-1
9.2.0782-1
vim Vim<9.2.0736
debian/vim<=2:8.2.2434-3+deb11u1, <=2:8.2.2434-3+deb11u3, <=2:9.0.1378-2+deb12u2, <=2:9.1.1230-2, <=2:9.2.0524-1
2:9.2.0782-1

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade to a fixed release to a version that resolves this vulnerability.

    Fixed in 9.2.0782-1
  2. Upgrade

    Upgrade debian/vim to a version that resolves this vulnerability.

    Fixed in 2:9.2.0782-1
  3. Upgrade

    Upgrade Vim (PHP omni-completion) to a version that resolves this vulnerability.

    Fixed in 9.2.0736

Event History

Jul 9, 2026
CVE Published
via MITRE·10:39 PM
Data Sourced
via MITRE·10:39 PM
DescriptionWeakness
Data Sourced
via NVD·11:17 PM
RemedyDescriptionSeverityWeaknessAffected Software
Jul 11, 2026
Data Sourced
via Microsoft·08:01 AM
DescriptionSeverityWeaknessAffected Software
Updated
via Microsoft·08:01 AM
DescriptionSeverity
Jul 14, 2026
Data Sourced
via Ubuntu·08:29 PM
RemedyDescriptionSeverityAffected Software
Data Sourced
via Launchpad·08:30 PM
Description
Data Sourced
via Debian·08:30 PM
DescriptionAffected Software
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2026-59856?

The severity of CVE-2026-59856 is high, with a CVSS score of 8.4.

2

What systems are affected by CVE-2026-59856?

CVE-2026-59856 affects Vim versions prior to 9.2.0736.

3

How can CVE-2026-59856 be exploited?

CVE-2026-59856 can be exploited for arbitrary code execution via the PHP omni-completion feature in Vim.

4

How do I fix CVE-2026-59856?

To fix CVE-2026-59856, upgrade to Vim version 9.2.0736 or later.

5

What type of vulnerability is CVE-2026-59856?

CVE-2026-59856 is classified as a Code Injection vulnerability.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203
CVE-2026-59856 - Vim: Arbitrary Code Execution via PHP Omni-Completion - SecAlerts