diff --git a/meta/recipes-support/vim/files/CVE-2026-57456.patch b/meta/recipes-support/vim/files/CVE-2026-57456.patch
new file mode 100644
index 0000000000..9a4155ef04
--- /dev/null
+++ b/meta/recipes-support/vim/files/CVE-2026-57456.patch
@@ -0,0 +1,149 @@
+From cce141c42740f122dd8486ae04e21c2a81016ba8 Mon Sep 17 00:00:00 2001
+From: Christian Brabandt <cb@256bit.org>
+Date: Sun, 21 Jun 2026 19:50:56 +0000
+Subject: [PATCH] patch 9.2.0699: [security]: possible code execution with
+ python complete
+
+Problem:  [security]: possible code execution with python complete
+          (morningbread)
+Solution: Use repr() to quote the doc strings correctly
+
+Github Security Advisory:
+https://github.com/vim/vim/security/advisories/GHSA-ppj8-wqjf-6fp3
+
+Supported by AI
+
+Signed-off-by: Christian Brabandt <cb@256bit.org>
+
+Upstream-Status: Backport [https://github.com/vim/vim/commit/cce141c42740f122dd8486ae04e21c2a81016ba8]
+CVE: CVE-2026-57456
+Signed-off-by: Vijay Anusuri <vanusuri@mvista.com>
+---
+ runtime/autoload/python3complete.vim        |  9 +++++----
+ runtime/autoload/pythoncomplete.vim         |  9 +++++----
+ src/testdir/test_plugin_python3complete.vim | 15 +++++++++++++++
+ 3 files changed, 25 insertions(+), 8 deletions(-)
+
+diff --git a/runtime/autoload/python3complete.vim b/runtime/autoload/python3complete.vim
+index c4ef19d82f..f90cca74b3 100644
+--- a/runtime/autoload/python3complete.vim
++++ b/runtime/autoload/python3complete.vim
+@@ -2,7 +2,7 @@
+ " Maintainer: <vacancy>
+ " Previous Maintainer: Aaron Griffin <aaronmgriffin@gmail.com>
+ " Version: 0.10
+-" Last Updated: 2026 Jun 04
++" Last Updated: 2026 Jun 21
+ "
+ " Roland Puntaier: this file contains adaptations for python3 and is parallel to pythoncomplete.vim
+ "
+@@ -22,6 +22,7 @@
+ "     previous code passed buffer-supplied expressions to exec() which
+ "     Python evaluates at definition time, allowing arbitrary code
+ "     execution via crafted def/class headers
++"   * use repr() on doc strings to prevent code execution
+ "
+ " v 0.9
+ "   * Fixed docstring parsing for classes and functions
+@@ -335,7 +336,7 @@ class Scope(object):
+ 
+     def get_code(self):
+         str = ""
+-        if len(self.docstr) > 0: str += '"""'+self.docstr+'"""\n'
++        if len(self.docstr) > 0: str += repr(self.docstr)+'\n'
+         str += 'class _PyCmplNoType:\n    def __getattr__(self,name):\n        return None\n'
+         for sub in self.subscopes:
+             str += sub.get_code()
+@@ -378,7 +379,7 @@ class Class(Scope):
+                        if _DOTTED_NAME_RE.match(s.strip())]
+         if len(safe_supers) > 0: str += '(%s)' % ','.join(safe_supers)
+         str += ':\n'
+-        if len(self.docstr) > 0: str += self.childindent()+'"""'+self.docstr+'"""\n'
++        if len(self.docstr) > 0: str += self.childindent()+repr(self.docstr)+'\n'
+         if len(self.subscopes) > 0:
+             for s in self.subscopes: str += s.get_code()
+         else:
+@@ -401,7 +402,7 @@ class Function(Scope):
+         safe_params = [p for p in safe_params if p]
+         str = "%sdef %s(%s):\n" % \
+             (self.currentindent(),self.name,','.join(safe_params))
+-        if len(self.docstr) > 0: str += self.childindent()+'"""'+self.docstr+'"""\n'
++        if len(self.docstr) > 0: str += self.childindent()+repr(self.docstr)+'\n'
+         str += "%spass\n" % self.childindent()
+         return str
+ 
+diff --git a/runtime/autoload/pythoncomplete.vim b/runtime/autoload/pythoncomplete.vim
+index 39b1efd299..d2f5d57b0c 100644
+--- a/runtime/autoload/pythoncomplete.vim
++++ b/runtime/autoload/pythoncomplete.vim
+@@ -2,7 +2,7 @@
+ " Maintainer: <vacancy>
+ " Previous Maintainer: Aaron Griffin <aaronmgriffin@gmail.com>
+ " Version: 0.10
+-" Last Updated: 2026 Jun 04
++" Last Updated: 2026 Jun 21
+ "
+ " Changes
+ " TODO:
+@@ -20,6 +20,7 @@
+ "     previous code passed buffer-supplied expressions to exec() which
+ "     Python evaluates at definition time, allowing arbitrary code
+ "     execution via crafted def/class headers
++"   * use repr() on doc strings to prevent code execution
+ "
+ " v 0.9
+ "   * Fixed docstring parsing for classes and functions
+@@ -350,7 +351,7 @@ class Scope(object):
+ 
+     def get_code(self):
+         str = ""
+-        if len(self.docstr) > 0: str += '"""'+self.docstr+'"""\n'
++        if len(self.docstr) > 0: str += repr(self.docstr)+'\n'
+         str += 'class _PyCmplNoType:\n    def __getattr__(self,name):\n        return None\n'
+         for sub in self.subscopes:
+             str += sub.get_code()
+@@ -393,7 +394,7 @@ class Class(Scope):
+                        if _DOTTED_NAME_RE.match(s.strip())]
+         if len(safe_supers) > 0: str += '(%s)' % ','.join(safe_supers)
+         str += ':\n'
+-        if len(self.docstr) > 0: str += self.childindent()+'"""'+self.docstr+'"""\n'
++        if len(self.docstr) > 0: str += self.childindent()+repr(self.docstr)+'\n'
+         if len(self.subscopes) > 0:
+             for s in self.subscopes: str += s.get_code()
+         else:
+@@ -416,7 +417,7 @@ class Function(Scope):
+         safe_params = [p for p in safe_params if p]
+         str = "%sdef %s(%s):\n" % \
+             (self.currentindent(),self.name,','.join(safe_params))
+-        if len(self.docstr) > 0: str += self.childindent()+'"""'+self.docstr+'"""\n'
++        if len(self.docstr) > 0: str += self.childindent()+repr(self.docstr)+'\n'
+         str += "%spass\n" % self.childindent()
+         return str
+ 
+diff --git a/src/testdir/test_plugin_python3complete.vim b/src/testdir/test_plugin_python3complete.vim
+index e2b0c6616d..590348ee4a 100644
+--- a/src/testdir/test_plugin_python3complete.vim
++++ b/src/testdir/test_plugin_python3complete.vim
+@@ -221,4 +221,19 @@ func Test_python3complete_allow_import_on_runs_imports()
+         \ 'g:pythoncomplete_allow_import=1 did not run the buffer import')
+ endfunc
+ 
++func Test_python3complete_no_exec_via_class_docstring()
++  " A class-body docstring is emitted verbatim between triple quotes by
++  " get_code() and runs at class-definition time during exec().  A single-
++  " quoted source docstring lets an embedded """ survive doc()'s leading/
++  " trailing quote strip and break out of the generated literal.
++  let marker = tempname()
++  call s:CompleteAndExpectNoMarker([
++        \ 'class Foo:',
++        \ '    ''x"""+open("' . marker . '", "w").close()+"""y''',
++        \ '    pass',
++        \ 'Foo.',
++        \ ], marker,
++        \ 'class docstring expression was evaluated during omni-completion')
++endfunc
++
+ " vim: shiftwidth=2 sts=2 expandtab
+-- 
+2.43.0
+
diff --git a/meta/recipes-support/vim/vim.inc b/meta/recipes-support/vim/vim.inc
index dec5b68324..008dbdb8df 100644
--- a/meta/recipes-support/vim/vim.inc
+++ b/meta/recipes-support/vim/vim.inc
@@ -29,6 +29,7 @@ SRC_URI = "git://github.com/vim/vim.git;branch=master;protocol=https;tag=v${PV}
            file://CVE-2026-57451.patch \
            file://CVE-2026-57454.patch \
            file://CVE-2026-57455.patch \
+           file://CVE-2026-57456.patch \
            "
 
 PV .= ".0340"
