Data Loss Vulnerability in Vim Text Editor
CVE-2025-29768

4.4MEDIUM

Key Information:

Vendor

Vim

Status
Vendor
CVE Published:
13 March 2025

What is CVE-2025-29768?

The Vim text editor is susceptible to potential data loss when handling specially crafted zip files in the zip.vim plugin. Users of versions prior to 9.1.1198 are advised to be cautious, as invoking these crafted zip files requires the user to open them in Vim and execute the 'x' command on suspicious filenames. This vulnerability has been addressed in patch 9.1.1198, which provides necessary protections against such exploits.

Affected Version(s)

vim < 9.1.1198

References

CVSS V3.1

Score:
4.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.