PT-2026-29691 · Vim+3 · Vim+4

Mmajchr

·

Published

2026-04-02

·

Updated

2026-06-03

·

CVE-2026-35177

CVSS v3.1

7.1

High

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H
Name of the Vulnerable Software and Affected Versions Vim versions prior to 9.2.0280
Description A path traversal bypass in Vim's zip.vim plugin allows overwriting of arbitrary files when opening specially crafted zip archives. This circumvents a previous fix.
Recommendations Update to version 9.2.0280 or later.

Fix

Path traversal

Weakness Enumeration

Related Identifiers

ALSA-2026:22711
BDU:2026-05671
CVE-2026-35177
ECHO-33BB-95D6-B867
MGASA-2026-0083
OESA-2026-2177
USN-8213-1
USN-8246-1

Affected Products

Linuxmint
Red Os
Ubuntu
Vim
Zip.Vim