cbcvebase.
CVE-2025-29768
published 2025-03-13

CVE-2025-29768: Vim, a text editor, is vulnerable to potential data loss with zip.vim and special crafted zip files in versions prior to 9.1.1198. The impact is medium because…

PriorityP418medium4.4CVSS 3.1
AVLACLPRNUIRSUCLILAN
EPSS
0.34%
26.7th percentile
Vim, a text editor, is vulnerable to potential data loss with zip.vim and special crafted zip files in versions prior to 9.1.1198. The impact is medium because a user must be made to view such an archive with Vim and then press 'x' on such a strange filename. The issue has been fixed as of Vim patch v9.1.1198.

Affected

8 ranges
VendorProductVersion rangeFixed in
debianvim< vim 2:9.1.1230-1 (forky)vim 2:9.1.1230-1 (forky)
msrcazl3_vim_9.1.1164-1_on_azure_linux_3.0
msrcazl3_vim_9.1.1198-1_on_azure_linux_3.0
msrccbl2_vim_9.1.0791-4_on_cbl_mariner_2.0
msrccbl2_vim_9.1.1198-1_on_cbl_mariner_2.0
vimvim< 9.1.11989.1.1198
vimvim>= 0 < 2:9.1.1230-12:9.1.1230-1
vimvim>= 0 < 2:9.1.1230-12:9.1.1230-1

CVSS provenance

nvdv3.14.4MEDIUMCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N
osv4.4MEDIUM
vendor_debian4.4MEDIUM
vendor_msrc4.4MEDIUM
vendor_redhat4.4MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.