CVE-2025-53905

EUVD-2025-21555
Vim is an open source, command line text editor. Prior to version 9.1.1552, a path traversal issue in Vim’s tar.vim plugin can allow overwriting of arbitrary files when opening specially crafted tar archives. Impact is low because this exploit requires direct user interaction. However, successfully exploitation can lead to overwriting sensitive files or placing executable code in privileged locations, depending on the permissions of the process editing the archive. The victim must edit such a file using Vim which will reveal the filename and the file content, a careful user may suspect some strange things going on. Successful exploitation could results in the ability to execute arbitrary commands on the underlying operating system. Version 9.1.1552 contains a patch for the vulnerability.
Path Traversal
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
4.1 MEDIUM
LOCAL
HIGH
NONE
CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:C/C:N/I:L/A:L
Base Score
CVSS 3.x
EPSS Score
Percentile: 22%
Affected Products (NVD)
VendorProductVersion
vimvim
𝑥
< 9.1.1552
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
vim
bookworm
no-dsa
bullseye
postponed
bullseye (security)
vulnerable
forky
2:9.2.0524-1
fixed
sid
2:9.2.0524-1
fixed
trixie
no-dsa
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
vim
bionic
ignored
focal
ignored
jammy
ignored
noble
Fixed 2:9.1.0016-1ubuntu7.9
released
plucky
Fixed 2:9.1.0967-1ubuntu4.1
released
trusty
ignored
xenial
ignored
openSUSE logo
openSUSE / SLES Releases
openSUSE Product
Release
gvim
suse enterprise server 15 SP4
9.1.1629-150000.5.78.1
fixed
vim
suse enterprise desktop 15 SP6
9.1.1629-150500.20.33.1
fixed
suse enterprise desktop 15 SP7
9.1.1629-150500.20.33.1
fixed
suse enterprise sap 15 SP6
9.1.1629-150500.20.33.1
fixed
suse enterprise sap 15 SP7
9.1.1629-150500.20.33.1
fixed
suse enterprise server 15 SP4
9.1.1629-150000.5.78.1
fixed
suse enterprise server 15 SP6
9.1.1629-150500.20.33.1
fixed
suse enterprise server 15 SP7
9.1.1629-150500.20.33.1
fixed
vim-data
suse enterprise desktop 15 SP6
9.1.1629-150500.20.33.1
fixed
suse enterprise desktop 15 SP7
9.1.1629-150500.20.33.1
fixed
suse enterprise sap 15 SP6
9.1.1629-150500.20.33.1
fixed
suse enterprise sap 15 SP7
9.1.1629-150500.20.33.1
fixed
suse enterprise server 15 SP4
9.1.1629-150000.5.78.1
fixed
suse enterprise server 15 SP6
9.1.1629-150500.20.33.1
fixed
suse enterprise server 15 SP7
9.1.1629-150500.20.33.1
fixed
vim-data-common
suse enterprise desktop 15 SP6
9.1.1629-150500.20.33.1
fixed
suse enterprise desktop 15 SP7
9.1.1629-150500.20.33.1
fixed
suse enterprise sap 15 SP6
9.1.1629-150500.20.33.1
fixed
suse enterprise sap 15 SP7
9.1.1629-150500.20.33.1
fixed
suse enterprise server 15 SP4
9.1.1629-150000.5.78.1
fixed
suse enterprise server 15 SP6
9.1.1629-150500.20.33.1
fixed
suse enterprise server 15 SP7
9.1.1629-150500.20.33.1
fixed
vim-small
suse enterprise desktop 15 SP6
9.1.1629-150500.20.33.1
fixed
suse enterprise desktop 15 SP7
9.1.1629-150500.20.33.1
fixed
suse enterprise sap 15 SP6
9.1.1629-150500.20.33.1
fixed
suse enterprise sap 15 SP7
9.1.1629-150500.20.33.1
fixed
suse enterprise server 15 SP4
9.1.1629-150000.5.78.1
fixed
suse enterprise server 15 SP6
9.1.1629-150500.20.33.1
fixed
suse enterprise server 15 SP7
9.1.1629-150500.20.33.1
fixed
Red Hat logo
Red Hat Enterprise Linux Releases
Red Hat Product
Release
vim-X11
RHEL 8
2:8.0.1763-21.el8_10
fixed
RHEL 9
2:8.2.2637-23.el9_7
fixed
vim-common
RHEL 8
2:8.0.1763-21.el8_10
fixed
RHEL 9
2:8.2.2637-23.el9_7
fixed
vim-enhanced
RHEL 8
2:8.0.1763-21.el8_10
fixed
RHEL 9
2:8.2.2637-23.el9_7
fixed
vim-filesystem
RHEL 8
2:8.0.1763-21.el8_10
fixed
RHEL 9
2:8.2.2637-23.el9_7
fixed
vim-minimal
RHEL 8
2:8.0.1763-21.el8_10
fixed
RHEL 9
2:8.2.2637-23.el9_7
fixed