See how vim project compares to other vendors in security performance
An issue in Vim Project v9.2.0389 and earlier allows a local attacker to execute arbitrary code via the vmsfixfilename() function within file vim/src/osvms.c
VSCodeVim before 1.19.0 allows attackers to execute arbitrary code via a crafted workspace configuration.