See how neovim compares to other vendors in security performance
A flaw has been found in Neovim up to 0.12.2. Affected by this issue is the function M.read of the file runtime/lua/vim/secure.lua of the component View Branch. Executing a manipulation of the argument path can lead to command injection. It is possible to launch the attack on the local host. The exploit has been published and may be used. This patch is called f83e0dcaf8cf18de94828341b0a1a61a86c75baf. A patch should be applied to remediate this issue.
Last updated 21 May 2026
Vim is an open source, command line text editor. Prior to version 9.1.2132, a heap buffer overflow vulnerability exists in Vim's tag file resolution logic when processing the 'helpfile' option. The vulnerability is located in the gettagfname() function in src/tag.c. When processing help file tags, Vim copies the user-controlled 'helpfile' option value into a fixed-size heap buffer of MAXPATHL + 1 bytes (typically 4097 bytes) using an unsafe STRCPY() operation without any bounds checking. This issue has been patched in version 9.1.2132.
heap-buffer-overflow with visual mode in Vim < 9.1.1003
Last updated 5 September 2024
Vim < v9.1.0648 has a double-free in dialogchanged()
Last updated 24 July 2024
Last updated 24 July 2024
Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.1873.
Last updated 24 July 2024
Last updated 24 July 2024
Last updated 24 July 2024
Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.1331.
Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.1848.
Integer Overflow or Wraparound in GitHub repository vim/vim prior to 9.0.1846.
Accounts. A privacy issue was addressed with improved private data redaction for log entries.
Incorrect Calculation of Buffer Size in GitHub repository vim/vim prior to 9.0.1378.
Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.1376.
AMD. A buffer overflow issue was addressed with improved memory handling.
AMD. A buffer overflow issue was addressed with improved memory handling.
AMD. A buffer overflow issue was addressed with improved memory handling.
Last updated 24 July 2024
Heap based buffer overflow in vim/vim 9.0.0946 and below by allowing an attacker to CTRL-W gf in the expression used in the RHS of the substitute command.
Last updated 24 July 2024
Last updated 24 July 2024
Stack-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.0577.
Last updated 24 July 2024
Last updated 24 July 2024
Last updated 24 July 2024
Last updated 21 August 2024