Path Traversal Vulnerability in Vim's Zip.vim Plugin
CVE-2025-53906
4.1MEDIUM
What is CVE-2025-53906?
Vim, an open source command line text editor, is vulnerable to a path traversal issue in its zip.vim plugin prior to version 9.1.1551. This vulnerability allows an attacker to exploit specially crafted zip archives, potentially leading to the overwriting of arbitrary files. Although the risk requires user interaction to edit a compromised file, the exploitation can result in the execution of arbitrary commands on the host operating system, depending on the process’s privileges. Users are encouraged to update to the latest version to mitigate this vulnerability and ensure the security of their file system.
Affected Version(s)
vim < 9.1.1551