<div dir="ltr">Here&#39;s the vim zero-day discussed last night:<div><br><div><a href="https://www.csoonline.com/article/4153288/vim-and-gnu-emacs-claude-code-helpfully-found-zero-day-exploits-for-both.html">https://www.csoonline.com/article/4153288/vim-and-gnu-emacs-claude-code-helpfully-found-zero-day-exploits-for-both.html</a></div><div><br></div></div><div><i><span style="color:rgb(12,12,12);font-family:graphik,sans-serif;letter-spacing:-0.18px">\u201cAn attacker who can deliver a crafted file to a victim achieves arbitrary command execution with the privileges of the user running Vim,\u201d Vim maintainers noted </span><a href="https://github.com/vim/vim/security/advisories/GHSA-2gmj-rpqf-pxvh" target="_blank" rel="noreferrer noopener" style="box-sizing:border-box;color:rgb(12,12,12);font-family:graphik,sans-serif;letter-spacing:-0.18px">in their security advisory</a><span style="color:rgb(12,12,12);font-family:graphik,sans-serif;letter-spacing:-0.18px">. \u201cThe attack requires only that the victim opens the file; no further interaction is needed.\u201d</span></i></div><div><br></div><div>I forgot to mention an emacs flaw was also discovered.</div><div><br></div><div>Greg</div><div><br></div></div>