PT-2026-29691 · Vim+4 · Zip.Vim+5

·

CVE-2026-35177

·

Published

2026-04-02

·

Updated

2026-07-02

CVSS v3.1

7.1

High

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H
Name of the Vulnerable Software and Affected Versions Vim versions prior to 9.2.0280
Description A path traversal bypass in Vim's zip.vim plugin allows overwriting of arbitrary files when opening specially crafted zip archives. This circumvents a previous fix.
Recommendations Update to version 9.2.0280 or later.

Exploit

Fix

DoS

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2026:22711
ALSA-2026:22717
ALSA-2026:22730
BDU:2026-05671
CVE-2026-35177
ECHO-33BB-95D6-B867
GHSA-JC86-W7VM-8P24
MGASA-2026-0083
OESA-2026-2177
RHSA-2026:22711
RHSA-2026:22717
RHSA-2026:22730
RHSA-2026:33453
RHSA-2026:34476
RHSA-2026:34477
USN-8213-1
USN-8246-1
USN-8500-1

Affected Products

Linuxmint
Red Os
Rocky Linux
Ubuntu
Vim
Zip.Vim