Junglewise Threat Intelligence

CVE-2026-25749: Vim heap buffer overflow in helpfile option handling

CVE-2026-25749 · Severity: medium · CVSS 6.6 · Published 2026-02-06

Technologies: Vim. Vendors: Vim.

Executive brief

Vim is a widely used open-source text editor. A security vulnerability in how Vim handles its help file settings could allow an attacker to crash the application or potentially gain unauthorized control over a user's system. To exploit this, an attacker would need to trick a user into setting a specially crafted long file path as their help file and then triggering the help command.

Technical details

A heap buffer overflow exists in the get_tagfname() function within src/tag.c. The vulnerability is caused by the use of an unsafe STRCPY() operation that copies the user-controlled 'helpfile' option (p_hf) into a fixed-size heap buffer (buf) of MAXPATHL + 1 bytes without bounds checking. An attacker can trigger this by setting a 'helpfile' string exceeding 4097 bytes and executing the :help command, leading to heap memory corruption. While primarily a Denial of Service risk, the nature of heap overflows allows for potential arbitrary code execution depending on heap layout. The issue is patched in Vim version 9.1.2132 by replacing the unsafe copy with a length-limited strncpy.

Affected products

  • Vim Vim Prior to 9.1.2132
  • Neovim Neovim Up to and including 0.11.6

Timeline

  • 2026-02-05: patched: Vim patch 9.1.2132 released
  • 2026-02-05: advisory: GitHub Security Advisory GHSA-5w93-4g67-mm43 published
  • 2026-02-06: disclosed: CVE-2026-25749 published to NVD

References

Related threats