Path Traversal Vulnerability in Vim's Zip.vim Plugin
CVE-2025-53906

4.1MEDIUM

Key Information:

Vendor

Vim

Status
Vendor
CVE Published:
15 July 2025

What is CVE-2025-53906?

Vim, an open source command line text editor, is vulnerable to a path traversal issue in its zip.vim plugin prior to version 9.1.1551. This vulnerability allows an attacker to exploit specially crafted zip archives, potentially leading to the overwriting of arbitrary files. Although the risk requires user interaction to edit a compromised file, the exploitation can result in the execution of arbitrary commands on the host operating system, depending on the process’s privileges. Users are encouraged to update to the latest version to mitigate this vulnerability and ensure the security of their file system.

Affected Version(s)

vim < 9.1.1551

References

CVSS V3.1

Score:
4.1
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-53906 : Path Traversal Vulnerability in Vim's Zip.vim Plugin