CVE-2025-66476
HIGHVim < 9.1.1947 - Uncontrolled Search Path Element on Windows via Current Working Directory
Title source: llmDescription
Vim is an open source, command line text editor. Prior to version 9.1.1947, an uncontrolled search path vulnerability on Windows allows Vim to execute malicious executables placed in the current working directory for the current edited file. On Windows, when using cmd.exe as a shell, Vim resolves external commands by searching the current working directory before system paths. When Vim invokes tools such as findstr for :grep, external commands or filters via :!, or compiler/:make commands, it may inadvertently run a malicious executable present in the same directory as the file being edited. The issue affects Vim for Windows prior to version 9.1.1947.
References (4)
Core 4
Core References
Patch, Vendor Advisory x_refsource_confirm
https://github.com/vim/vim/security/advisories/GHSA-g77q-xrww-p834
Patch x_refsource_misc
https://github.com/vim/vim/commit/083ec6d9a3b7b09006e0ce69ac802597d25
Release Notes x_refsource_misc
https://github.com/vim/vim/releases/tag/v9.1.1947
Mailing List, Patch, Third Party Advisory
http://www.openwall.com/lists/oss-security/2025/12/02/5
Scores
CVSS v3
7.8
EPSS
0.0043
EPSS Percentile
34.2%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
total
Details
CWE
CWE-427
Status
published
Products (1)
vim/vim
< 9.1.1947
Published
Dec 02, 2025
Tracked Since
Feb 18, 2026