CVE-2025-53906
published 2025-07-15CVE-2025-53906: Vim is an open source, command line text editor. Prior to version 9.1.1551, a path traversal issue in Vim’s zip.vim plugin can allow overwriting of arbitrary…
PriorityP422medium4.1CVSS 3.1
AVLACHPRNUIRSCCNILAL
EPSS
0.73%
50.2th percentile
Vim is an open source, command line text editor. Prior to version 9.1.1551, a path traversal issue in Vim’s zip.vim plugin can allow overwriting of arbitrary files when opening specially crafted zip archives. Impact is low because this exploit requires direct user interaction. However, successfully exploitation can lead to overwriting sensitive files or placing executable code in privileged locations, depending on the permissions of the process editing the archive. The victim must edit such a file using Vim which will reveal the filename and the file content, a careful user may suspect some strange things going on. Successful exploitation could results in the ability to execute arbitrary commands on the underlying operating system. Version 9.1.1551 contains a patch for the vulnerability.
Affected
11 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | macos_tahoe | — | — |
| debian | vim | < vim 2:9.1.1829-1 (forky) | vim 2:9.1.1829-1 (forky) |
| debian | vim | < vim 2:9.2.0315-1 (sid) | vim 2:9.2.0315-1 (sid) |
| msrc | azl3_vim_9.1.1198-1_on_azure_linux_3.0 | — | — |
| msrc | azl3_vim_9.1.1552-1_on_azure_linux_3.0 | — | — |
| msrc | cbl2_vim_9.1.1198-1_on_cbl_mariner_2.0 | — | — |
| msrc | cbl2_vim_9.1.1552-1_on_cbl_mariner_2.0 | — | — |
| vim | vim | < 9.2.0280 | 9.2.0280 |
| vim | vim | < 9.1.1551 | 9.1.1551 |
| vim | vim | < 9.2.0280 | 9.2.0280 |
| vim | vim | >= 0 < 2:9.1.1829-1 | 2:9.1.1829-1 |
CVSS provenance
nvdv3.14.1MEDIUMCVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:C/C:N/I:L/A:L
osv4.1MEDIUM
vendor_debian4.1MEDIUM
vendor_msrc4.1MEDIUM
vendor_redhat4.1MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
CVE-2026-35177: Vim is an open source, command line text editor
osv·2026-04-06·CVSS 4.1
CVE-2026-35177 [MEDIUM] CVE-2026-35177: Vim is an open source, command line text editor
Vim is an open source, command line text editor. Prior to 9.2.0280, a path traversal bypass in Vim's zip.vim plugin allows overwriting of arbitrary files when opening specially crafted zip archives, circumventing the previous fix for CVE-2025-53906. This vulnerability is fixed in 9.2.0280.
OSV
CVE-2025-53906: Vim is an open source, command line text editor
osv·2025-07-15·CVSS 4.1
CVE-2025-53906 [MEDIUM] CVE-2025-53906: Vim is an open source, command line text editor
Vim is an open source, command line text editor. Prior to version 9.1.1551, a path traversal issue in Vim’s zip.vim plugin can allow overwriting of arbitrary files when opening specially crafted zip archives. Impact is low because this exploit requires direct user interaction. However, successfully exploitation can lead to overwriting sensitive files or placing executable code in privileged locations, depending on the permissions of the process editing the archive. The victim must edit such a file using Vim which will reveal the filename and the file content, a careful user may suspect some strange things going on. Successful exploitation could results in the ability to execute arbitrary commands on the underlying operating system. Version 9.1.1551 contains a patch for the vulnerability.
Red Hat
vim: zip.vim: Vim zip.vim plugin: Arbitrary file overwrite via path traversal bypass
vendor_redhat·2026-04-06·CVSS 4.1
CVE-2026-35177 [MEDIUM] CWE-22 vim: zip.vim: Vim zip.vim plugin: Arbitrary file overwrite via path traversal bypass
vim: zip.vim: Vim zip.vim plugin: Arbitrary file overwrite via path traversal bypass
Vim is an open source, command line text editor. Prior to 9.2.0280, a path traversal bypass in Vim's zip.vim plugin allows overwriting of arbitrary files when opening specially crafted zip archives, circumventing the previous fix for CVE-2025-53906. This vulnerability is fixed in 9.2.0280.
A flaw was found in Vim's zip.vim plugin. A local user could be tricked into opening a specially crafted zip archive, which would allow a path traversal bypass. This vulnerability enables an attacker to overwrite arbitrary files on the system, potentially leading to data integrity issues or further system compromise.
Statement: There's a flaw in `zip.vim` plugin in Vim, allowing a local attacker to overwrite arbitrary
Debian
CVE-2026-35177: vim - Vim is an open source, command line text editor. Prior to 9.2.0280, a path trave...
vendor_debian·2026·CVSS 4.1
CVE-2026-35177 [MEDIUM] CVE-2026-35177: vim - Vim is an open source, command line text editor. Prior to 9.2.0280, a path trave...
Vim is an open source, command line text editor. Prior to 9.2.0280, a path traversal bypass in Vim's zip.vim plugin allows overwriting of arbitrary files when opening specially crafted zip archives, circumventing the previous fix for CVE-2025-53906. This vulnerability is fixed in 9.2.0280.
Scope: local
bookworm: open
bullseye: open
forky: open
sid: resolved (fixed in 2:9.2.0315-1)
trixie: open
Apple
CVE-2025-53906: macOS Tahoe 26.1
vendor_apple·2025-11-03·CVSS 4.1
CVE-2025-53906 [MEDIUM] CVE-2025-53906: macOS Tahoe 26.1
Apple Security Update: About the security content of macOS Tahoe 26.1
Product: macOS Tahoe
Version: 26.1
CVE: CVE-2025-53906
Component: CVE-2025-53906
Ubuntu
Vim vulnerabilities
vendor_ubuntu·2025-09-15
CVE-2025-53906 Vim vulnerabilities
Title: Vim vulnerabilities
Summary: Several security issues were fixed in Vim.
It was discovered that Vim incorrectly handled file extraction when opening
maliciously crafted zip or tar archives. An attacker could possibly use
this issue to create or overwrite files on the system and execute arbitrary
code.
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
vim: Vim path traversal
vendor_redhat·2025-07-15·CVSS 4.1
CVE-2025-53906 [MEDIUM] CWE-22 vim: Vim path traversal
vim: Vim path traversal
Vim is an open source, command line text editor. Prior to version 9.1.1551, a path traversal issue in Vim’s zip.vim plugin can allow overwriting of arbitrary files when opening specially crafted zip archives. Impact is low because this exploit requires direct user interaction. However, successfully exploitation can lead to overwriting sensitive files or placing executable code in privileged locations, depending on the permissions of the process editing the archive. The victim must edit such a file using Vim which will reveal the filename and the file content, a careful user may suspect some strange things going on. Successful exploitation could results in the ability to execute arbitrary commands on the underlying operating system. Version 9.1.1551 contains a patch
Microsoft
Vim has path traversal issue with zip.vim and special crafted zip archives
vendor_msrc·2025-07-08·CVSS 4.1
CVE-2025-53906 [MEDIUM] CWE-22 Vim has path traversal issue with zip.vim and special crafted zip archives
Vim has path traversal issue with zip.vim and special crafted zip archives
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See this blog post for more information. If impact to additional products is identified, we will update the CVE to reflect this.
Mariner: Mariner
GitHub_M: GitHub_M
Customer Action Required: Yes
Remediation: CBL-Mariner Releases
Debian
CVE-2025-53906: vim - Vim is an open source, command line text editor. Prior to version 9.1.1551, a pa...
vendor_debian·2025·CVSS 4.1
CVE-2025-53906 [MEDIUM] CVE-2025-53906: vim - Vim is an open source, command line text editor. Prior to version 9.1.1551, a pa...
Vim is an open source, command line text editor. Prior to version 9.1.1551, a path traversal issue in Vim’s zip.vim plugin can allow overwriting of arbitrary files when opening specially crafted zip archives. Impact is low because this exploit requires direct user interaction. However, successfully exploitation can lead to overwriting sensitive files or placing executable code in privileged locations, depending on the permissions of the process editing the archive. The victim must edit such a file using Vim which will reveal the filename and the file content, a careful user may suspect some strange things going on. Successful exploitation could results in the ability to execute arbitrary commands on the underlying operating system. Version 9.1.1551 contains a patch for the vulnerability.
S
No detection rules found.
No public exploits indexed.
Wiz
CVE-2026-35177 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 4.1
CVE-2026-35177 [MEDIUM] CVE-2026-35177 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-35177 :
Vim vulnerability analysis and mitigation
Vim is an open source, command line text editor. Prior to 9.2.0280, a path traversal bypass in Vim's zip.vim plugin allows overwriting of arbitrary files when opening specially crafted zip archives, circumventing the previous fix for CVE-2025-53906. This vulnerability is fixed in 9.2.0280.
Source : NVD
## 4.1
Score
Published April 6, 2026
Severity MEDIUM
CNA Score 4.1
Affected Technologies
Vim
Linux Red Hat
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 3.7
Exploitation Probability (EPSS) N/A
Affected packages and libraries
vim-data
xxd
Sources
NVD
Alpine 3.23, edge Severity MEDIUM Has Fix Added at: Apr 02, 2026
De
Bugzilla
CVE-2026-35177 vim: zip.vim: Vim zip.vim plugin: Arbitrary file overwrite via path traversal bypass
bugzilla·2026-04-06·CVSS 4.1
CVE-2026-35177 [MEDIUM] CVE-2026-35177 vim: zip.vim: Vim zip.vim plugin: Arbitrary file overwrite via path traversal bypass
CVE-2026-35177 vim: zip.vim: Vim zip.vim plugin: Arbitrary file overwrite via path traversal bypass
Vim is an open source, command line text editor. Prior to 9.2.0280, a path traversal bypass in Vim's zip.vim plugin allows overwriting of arbitrary files when opening specially crafted zip archives, circumventing the previous fix for CVE-2025-53906. This vulnerability is fixed in 9.2.0280.
Bugzilla
CVE-2025-53906 vim: Vim path traversal
bugzilla·2025-07-15·CVSS 4.1
CVE-2025-53906 [MEDIUM] CVE-2025-53906 vim: Vim path traversal
CVE-2025-53906 vim: Vim path traversal
Vim is an open source, command line text editor. Prior to version 9.1.1551, a path traversal issue in Vim’s zip.vim plugin can allow overwriting of arbitrary files when opening specially crafted zip archives. Impact is low because this exploit requires direct user interaction. However, successfully exploitation can lead to overwriting sensitive files or placing executable code in privileged locations, depending on the permissions of the process editing the archive. The victim must edit such a file using Vim which will reveal the filename and the file content, a careful user may suspect some strange things going on. Successful exploitation could results in the ability to execute arbitrary commands on the underlying operating system. Version 9.1.1551 c
https://github.com/vim/vim/commit/586294a04179d855c3d1d4ee5ea83931963680b8https://github.com/vim/vim/security/advisories/GHSA-r2fw-9cw4-mj86http://www.openwall.com/lists/oss-security/2025/07/15/2http://www.openwall.com/lists/oss-security/2026/04/01/4https://github.com/vim/vim/security/advisories/GHSA-r2fw-9cw4-mj86
2025-07-15
Published