CVE-2026-47162 in netrw

A directory name that runs code in your editor, one session later

CVSS 8.8 High (NVD) Confirmed on Neovim v0.12.5 and the VS Code Neovim extension
1Browse in and nothing happens; the next nvim . runs the payload
2Vulnerable vs. patched (vim 9.2.0495)
3Also works in VS Code (vscode-neovim)

The bug

Attack chainAttacker repo, git clone, session 1 browse, netrw writes .netrwhist, then in a later session netrw sources it and runs call system as the victim.1 Attacker repocrafted directory name2 git clonevictim clones it3 Session 1: nvim .browse into the directory4 netrw writes .netrwhistunescaped path saved to disk5 Session 2: open a directorynetrw sources .netrwhist6 call system(...)runs as the victimlater, new sessionpersistence point Attack chain1 Attacker repocrafted directory name2 git clonevictim clones it3 Session 1: nvim .browse into the directory4 netrw writes .netrwhistunescaped path saved to disk5 Session 2: open a directorynetrw sources .netrwhist6 call system(...)runs as the victimlater, new sessionpersistence point

The same chain fires through vscode-neovim.

The crafted directory name

assets'|call system('id>PWNED.txt')|let x='

What netrw writes to .netrwhist, with the injected part highlighted

let g:netrw_dirhist_1='/home/victim/totally-normal-project/assets'|call system('id>PWNED.txt')|let x=''

The vulnerable line and the fix in s:NetrwBookHistSave()

- call setline(lastline,'let g:netrw_dirhist_'.cnt."='".g:netrw_dirhist_{cnt}."'")+ call setline(lastline,'let g:netrw_dirhist_'.cnt."=".string(g:netrw_dirhist_{cnt}))

Fixed in vim 9.2.0495, still in Neovim v0.12.5. It needs two directory-browse actions.