๐Ÿ” CVE Alert

CVE-2026-11487

MEDIUM 5.3

Neovim View Branch secure.lua M.read command injection

CVSS Score
5.3
EPSS Score
0.2%
EPSS Percentile
39th

A flaw has been found in Neovim up to 0.12.2. Affected by this issue is the function M.read of the file runtime/lua/vim/secure.lua of the component View Branch. Executing a manipulation of the argument path can lead to command injection. It is possible to launch the attack on the local host. The exploit has been published and may be used. This patch is called f83e0dcaf8cf18de94828341b0a1a61a86c75baf. A patch should be applied to remediate this issue.

CWE CWE-77 CWE-74
Vendor n/a
Product neovim
Published Jun 8, 2026
Last Updated Jun 8, 2026
Stay Ahead of the Next One

Get instant alerts for n/a neovim

Be the first to know when new medium vulnerabilities affecting n/a neovim are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:O/RC:C
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability

Affected Versions

n/a / Neovim
0.12.0 0.12.1 0.12.2

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
vuldb.com: https://vuldb.com/vuln/369107 vuldb.com: https://vuldb.com/vuln/369107/cti vuldb.com: https://vuldb.com/cve/CVE-2026-11487 vuldb.com: https://vuldb.com/submit/834495 github.com: https://github.com/neovim/neovim/issues/39914 github.com: https://github.com/neovim/neovim/pull/39918 github.com: https://github.com/neovim/neovim/commit/f83e0dcaf8cf18de94828341b0a1a61a86c75baf github.com: https://github.com/neovim/neovim/

Credits

๐Ÿ” NanHang (VulDB User)