Commit: patch 9.2.0845: [security]: arbitrary Ex command execution during C omni-completion

Christian Brabandt <[email protected]>
Newsgroups gmane.editors.vim.devel
Message-ID <[email protected]>
patch 9.2.0845: [security]: arbitrary Ex command execution during C omni-completion

Commit: https://github.com/vim/vim/commit/2f628d8104958fa7421664f792ca6d4f7a39a10f
Author: Yasuhiro Matsumoto <[email protected]>
Date:   Fri Jul 17 09:11:42 2026 +0900

    patch 9.2.0845: [security]: arbitrary Ex command execution during C omni-completion
    
    Problem:  [security]: arbitrary Ex command execution during C
              omni-completion (Threonine)
    Solution: Match tags typeref literally to block Ex command injection
              (Yasuhiro Matsumoto).
    
    Escaping only "/" and "\" left the typeref able to break out of the
    :vimgrep pattern without a "/": an unclosed "[" makes vimgrep's pattern
    skipping fail, and the parser then treats a following "|" as a command
    separator, so the tag value runs as Ex commands during C omni-completion.
    Match the field literally with \V so no regex metacharacter can affect
    pattern parsing.
    
    Github Security Advisory:
    https://github.com/vim/vim/security/advisories/GHSA-cx73-phcg-3j5g
    
    Signed-off-by: Yasuhiro Matsumoto <[email protected]>
    Signed-off-by: Christian Brabandt <[email protected]>

diff --git a/runtime/autoload/ccomplete.vim b/runtime/autoload/ccomplete.vim
index dc3388b52..593789a84 100644
--- a/runtime/autoload/ccomplete.vim
+++ b/runtime/autoload/ccomplete.vim
@@ -599,8 +599,11 @@ def StructMembers( # {{{1
       if complete_check()
         return []
       endif
+      # Match "typename" literally (\V): escaping alone is not enough, as e.g.
+      # an unclosed "[" makes vimgrep's pattern skipping fail and the rest of
+      # the tag value is then parsed as Ex commands.
       execute 'silent! keepjumps noautocmd '
-        .. n .. 'vimgrep ' .. '/	' .. escape(typename, '/\') .. '\(	\|$\)/j '
+        .. n .. 'vimgrep ' .. '/	\V' .. escape(typename, '/\') .. '\m\(	\|$\)/j '
         .. fnames
 
       qflist = getqflist()
diff --git a/src/testdir/test_plugin_ccomplete.vim b/src/testdir/test_plugin_ccomplete.vim
index a635bd50b..c1754d17c 100644
--- a/src/testdir/test_plugin_ccomplete.vim
+++ b/src/testdir/test_plugin_ccomplete.vim
@@ -31,6 +31,32 @@ func Test_ccomplete_no_exec_via_typeref()
   unlet! g:ccomplete_injected
 endfunc
 
+" Escaping "/" and "\" is not enough: with no "/" in the payload, an unclosed
+" "[" makes vimgrep's pattern skipping fail, and the command parser then treats
+" the first "|" as a command separator.  The typeref must be matched literally.
+func Test_ccomplete_no_exec_via_typeref_bracket()
+  CheckUnix
+  let sentinel = tempname()
+  call delete(sentinel)
+  let tagsfile = s:WriteTags([
+        \ "myvar	main.c	/^x$/;\"	v	typeref:struct:[|call system('touch " .. sentinel .. "')|####",
+        \ ])
+
+  let save_tags = &tags
+  let &tags = tagsfile
+
+  new
+  call ccomplete#Complete(1, '')
+  call ccomplete#Complete(0, 'myvar.x')
+
+  call assert_false(filereadable(sentinel),
+        \ 'typeref field was executed as an Ex command during omni-completion')
+
+  bwipe!
+  let &tags = save_tags
+  call delete(sentinel)
+endfunc
+
 " A legitimate typeref must still drive struct-member completion: escaping the
 " field value must not break the normal path.
 func Test_ccomplete_typeref_completion_still_works()
diff --git a/src/version.c b/src/version.c
index 4bd76c0f5..a93ef0384 100644
--- a/src/version.c
+++ b/src/version.c
@@ -758,6 +758,8 @@ static char *(features[]) =
 
 static int included_patches[] =
 {   /* Add new patch number below this line */
+/**/
+    845,
 /**/
     844,
 /**/

-- 
-- 
You received this message from the "vim_dev" maillist.
Do not top-post! Type your reply below the text you are replying to.
For more information, visit http://www.vim.org/maillist.php

--- 
You received this message because you are subscribed to the Google Groups "vim_dev" group.
To unsubscribe from this group and stop receiving emails from it, send an email to [email protected].
To view this discussion visit https://groups.google.com/d/msgid/vim_dev/E1wnKtN-00BzPT-2B%40256bit.org.
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.