A flaw was found in Vim's netrw plugin. A crafted filename containing quote characters and expression fragments can break out of the quoted context during mark/unmark operations, allowing arbitrary Vimscript execution. This can be leveraged to run shell commands with the privileges of the user running Vim.
https://github.com/vim/vim/security/advisories/GHSA-66hr-7p6x-x5j3
https://bugzilla.redhat.com/show_bug.cgi?id=2460434