CVE-2025-53906: Vim has path traversal issue with zip.vim and special crafted zip archives
Admin Framework. A logic issue was addressed with improved checks.
Other sources
Admin Framework. The issue was addressed with improved checks.
— Apple
App Store. A logging issue was addressed with improved data redaction.
— Apple
Apple Account. A privacy issue was addressed with improved checks.
— Apple
Apple Neural Engine. The issue was addressed with improved memory handling.
— Apple
AppleMobileFileIntegrity. A downgrade issue affecting Intel-based Mac computers was addressed with additional code-signing restrictions.
— Apple
Credit
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 26.1 - Upgrade
Upgrade
Vim (zip.vim plugin)to a version that resolves this vulnerability.Fixed in 9.1.1551 - Compensating control
For the affected Vim zip.vim path traversal issue, ensure users do not open specially crafted zip archives with Vim (the described exploitation requires direct user interaction to open the crafted archive in Vim).
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2025-43471
- CVE-2025-43322
- CVE-2025-46313
- CVE-2025-43455
- CVE-2025-43447
- CVE-2025-43462
- CVE-2025-43390
- CVE-2025-43388
- CVE-2025-43466
- CVE-2025-43382
- CVE-2025-43468
- CVE-2025-43379
- CVE-2025-43378
- CVE-2025-43478
- CVE-2025-43407
- CVE-2025-43446
- CVE-2025-43465
- CVE-2025-43423
- CVE-2025-43497
- CVE-2025-43394
- CVE-2025-43448
- CVE-2025-43395
- CVE-2025-43461
- CVE-2025-43426
- CVE-2025-43401
- CVE-2025-43479
- CVE-2025-43436
- CVE-2025-43381
- CVE-2025-43445
- CVE-2025-43481
- CVE-2025-43470
- CVE-2025-46315
- CVE-2025-43387
- CVE-2025-43420
- CVE-2025-43464
- CVE-2025-43498
- CVE-2025-43507
- CVE-2025-43348
- CVE-2025-43474
- CVE-2025-43396
- CVE-2025-43444
- CVE-2025-43467
- CVE-2025-43398
- CVE-2025-43510
- CVE-2025-43520
- CVE-2025-43413
- CVE-2025-43494
- CVE-2025-43496
- CVE-2025-43386
- CVE-2025-43385
- CVE-2025-43384
- CVE-2025-43383
- CVE-2025-43377
- CVE-2025-43424
- CVE-2025-43364
- CVE-2025-43506
- CVE-2025-43389
- CVE-2025-43469
- CVE-2025-43411
- CVE-2025-43508
- CVE-2025-43405
- CVE-2025-43391
- CVE-2025-43393
- CVE-2025-46316
- CVE-2024-43398
- CVE-2024-49761
- CVE-2025-6442
- CVE-2025-43493
- CVE-2025-43503
- CVE-2025-43502
- CVE-2025-43406
- CVE-2025-43404
- CVE-2025-43339
- CVE-2025-43500
- CVE-2025-43335
- CVE-2025-43408
- CVE-2025-43476
- CVE-2025-30465
- CVE-2025-43414
- CVE-2025-43473
- CVE-2025-43499
- CVE-2025-43380
- CVE-2025-43477
- CVE-2025-43399
- CVE-2025-43336
- CVE-2025-43397
- CVE-2025-43409
- CVE-2025-43351
- CVE-2025-43463
- CVE-2025-32462
- CVE-2025-43334
- CVE-2025-43412
- CVE-2025-53906
- CVE-2025-43480
- CVE-2025-43458
- CVE-2025-43430
- CVE-2025-43427
- CVE-2025-43443
- CVE-2025-43441
- CVE-2025-43435
- CVE-2025-43425
- CVE-2025-43440
- CVE-2025-43438
- CVE-2025-43457
- CVE-2025-43434
- CVE-2025-43433
- CVE-2025-43431
- CVE-2025-43432
- CVE-2025-43429
- CVE-2025-43421
- CVE-2025-43392
- CVE-2025-43373
- CVE-2025-43402
- CVE-2025-43472
Frequently Asked Questions
What is the severity of CVE-2025-53906?
The severity of CVE-2025-53906 is considered low due to the requirement of direct user interaction for exploitation.
How do I fix CVE-2025-53906?
To fix CVE-2025-53906, users should upgrade to Vim version 9.1.1551 or later.
What type of vulnerability is CVE-2025-53906?
CVE-2025-53906 is a path traversal vulnerability that affects the zip.vim plugin in Vim.
Which versions of Vim are affected by CVE-2025-53906?
Vim versions prior to 9.1.1551 are affected by CVE-2025-53906.
What is the impact of CVE-2025-53906?
The impact of CVE-2025-53906 is low, as it requires the user to open specially crafted zip archives for exploitation.