Vulnerability record · CVE-2025-66476 · published 2 December 2025
CVE-2025-66476: Vim uncontrolled search path element vulnerability
Vim · Vim
Vim is an open source, command line text editor. Prior to version 9.1.1947, an uncontrolled search path vulnerability on Windows allows Vim to execute malicious executables placed in the current working directory for the current edited file. On Windows, when using cmd.exe as a shell, Vim resolves external commands by searching the current working directory before system paths. When Vim invokes tools such as findstr for :grep, external commands or filters via :!, or compiler/:make commands, it may inadvertently run a malicious executable present in the same directory as the file being edited. The issue affects Vim for Windows prior to version 9.1.1947.
Description
Vim is an open source, command line text editor. Prior to version 9.1.1947, an uncontrolled search path vulnerability on Windows allows Vim to execute malicious executables placed in the current working directory for the current edited file. On Windows, when using cmd.exe as a shell, Vim resolves external commands by searching the current working directory before system paths. When Vim invokes tools such as findstr for :grep, external commands or filters via :!, or compiler/:make commands, it may inadvertently run a malicious executable present in the same directory as the file being edited. The issue affects Vim for Windows prior to version 9.1.1947.
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://github.com/vim/vim/commit/083ec6d9a3b7b09006e0ce69ac802597d25 | Patch |
| https://github.com/vim/vim/releases/tag/v9.1.1947 | Release Notes |
| https://github.com/vim/vim/security/advisories/GHSA-g77q-xrww-p834 | PatchVendor Advisory |
| http://www.openwall.com/lists/oss-security/2025/12/02/5 | Mailing ListPatchThird Party Advisory |
Track CVE-2025-66476 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2025-66476), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.