Files
neovim/runtime/pack
zeertzjq c4ce10930c vim-patch:9.2.0663: [security]: runtime(netrw): code injection in local file deletion
Problem:  [security]: s:NetrwLocalRmFile() escapes only the backslash in
          the file name before passing it to :execute, so a name
          containing "|" injects arbitrary Ex commands when the file is
          deleted (cipher-creator)
Solution: Use fnameescape() to correctly escape the file name
          (Yasuhiro Matsumoto).

Github Security Advisory:
https://github.com/vim/vim/security/advisories/GHSA-vhh8-v6wx-hjjh

Supported by AI

55bc757a5d

Co-authored-by: Yasuhiro Matsumoto <mattn.jp@gmail.com>
2026-06-17 15:22:04 +08:00
..