CVE-2019-12735
HIGH 9.3EPSS 19.0%
getchar.c in Vim before 8.1.1365 and Neovim before 0.3.6 allows remote attackers to execute arbitrary OS commands via the :source! command in a modeline, as demonstrated by execute in Vim, and assert_fails or nvim_input in Neovim.
- CVSS v3.0
- 8.6 HIGH
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H - CVSS v2.0
- 9.3 HIGH
AV:N/AC:M/Au:N/C:C/I:C/A:C - EPSS
- 18.96% chance of exploitation in the next 30 days, 97th percentile
- Published
- 2019-06-05
- Updated
- 2025-11-11
Proof-of-concept exploits (6)
- numirias/security/blob/master/doc/2019-06-04_ace-vim-neovim.md
- datntsec/CVE-2019-127350★ · 2020-10-27
- nickylimjj/cve-2019-127351★ · 2021-05-28
- oldthree3/CVE-2019-12735-VIM-NEOVIM2★ · 2019-06-19
- st9007a/CVE-2019-127350★ · 2022-07-26
- vicmej/modeline-vim0★ · 2019-06-22