[NetSIG] vim zero-day (fixed) ... but not emacs

Greg H greg.horie at gmail.com
Fri Apr 24 07:49:37 PDT 2026


Here's the vim zero-day discussed last night:

https://www.csoonline.com/article/4153288/vim-and-gnu-emacs-claude-code-helpfully-found-zero-day-exploits-for-both.html

*“An attacker who can deliver a crafted file to a victim achieves arbitrary
command execution with the privileges of the user running Vim,” Vim
maintainers noted in their security advisory
<https://github.com/vim/vim/security/advisories/GHSA-2gmj-rpqf-pxvh>. “The
attack requires only that the victim opens the file; no further interaction
is needed.”*

I forgot to mention an emacs flaw was also discovered.

Greg
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://vicpimakers.ca/pipermail/netsig_vicpimakers.ca/attachments/20260424/57d04f5a/attachment.htm>


More information about the NetSIG mailing list