[NetSIG] vim zero-day (fixed) ... but not emacs

Mark G. netsig at palaceofretention.ca
Sun Apr 26 12:14:22 PDT 2026


Nice that it is patched.  I just noticed, however, that FreeBSD
ships plain old vi, not vim.  Is vi a default in Linux, or is
it vim instead?  Curious, are there essential features that
vim has that makes it more useful than vi?




On 4/24/26 07:49, Greg H wrote:
> Here's the vim zero-day discussed last night:
> 
> https://www.csoonline.com/article/4153288/vim-and-gnu-emacs-claude-code-helpfully-found-zero-day-exploits-for-both.html 
> <https://www.csoonline.com/article/4153288/vim-and-gnu-emacs-claude-code-helpfully-found-zero-day-exploits-for-both.html>
> 
> /“An attacker who can deliver a crafted file to a victim achieves arbitrary command execution with the privileges of the 
> user running Vim,” Vim maintainers noted in their security advisory <https://github.com/vim/vim/security/advisories/ 
> GHSA-2gmj-rpqf-pxvh>. “The attack requires only that the victim opens the file; no further interaction is needed.”/
> 
> I forgot to mention an emacs flaw was also discovered.
> 
> Greg
> 
> 


More information about the NetSIG mailing list