{"id":"CVE-2026-59856","aliases":["GHSA-fh26-8f79-wj97"],"url":"https://o3.security/vulnerability/CVE-2026-59856","summary":"Vim: Arbitrary Code Execution via PHP Omni-Completion","details":"Vim is an open source, command line text editor. Prior to 9.2.0736, the PHP omni-completion script in runtime/autoload/phpcomplete.vim interpolates a class or trait name, taken from the contents of the edited buffer, into a search() pattern that is run via win_execute() without escaping. A name containing a single quote can terminate the search() string argument early, and because the bar is honored as an Ex command separator, the remainder of the name is run as Ex commands; via the :! command this allows arbitrary operating-system command execution when a victim opens a crafted PHP file and invokes omni-completion. This issue is fixed in version 9.2.0736.","published":"2026-07-09T22:39:01.803Z","modified":"2026-08-12T16:09:54.064596Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[],"fix":{"url":"https://github.com/vim/vim/commit/43afc581a37a35762dd0ef292f038b9dc5680a24","label":"vim/vim@43afc58"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/59xxx/CVE-2026-59856.json"},{"type":"ADVISORY","url":"https://github.com/vim/vim/security/advisories/GHSA-fh26-8f79-wj97"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-59856"},{"type":"FIX","url":"https://github.com/vim/vim/commit/43afc581a37a35762dd0ef292f038b9dc5680a24"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T16:09:54.064596Z"}}