CVE-2026-11487 | Neovim up to 0.12.2 View Branch secure.lua M.read path command injection (Issue 39914)
A vulnerability labeled as critical has been found in Neovim up to 0.12.2. Affected by this issue is the function M.read of the file runtime/lua/vim/secure.lua of the component View Branch. Executing a manipulation of the argument path can lead to command injection.
This vulnerability is handled as CVE-2026-11487. It is possible to launch the attack on the local host. Additionally, an exploit exists.
A patch should be applied to remediate this issue.