CVE-2026-35177: Path traversal issue with zip.vim in Vim
Published Apr 6, 2026
·Updated
Last updated 2 July 2026
Other sources
Path traversal issue with zip.vim in Vim
— Microsoft
Vim is an open source, command line text editor. Prior to 9.2.0280, a path traversal bypass in Vim's zip.vim plugin allows overwriting of arbitrary files when opening specially crafted zip archives, circumventing the previous fix for CVE-2025-53906. This vulnerability is fixed in 9.2.0280.
— MITRE
Affected Software
4 affected componentsFixes available
Microsoft azl3 vim 9.2.0240-1
vim Vim<9.2.0280
debian/vim<=2:8.2.2434-3+deb11u1, <=2:8.2.2434-3+deb11u3, <=2:9.0.1378-2+deb12u2, <=2:9.1.1230-2
2:9.2.0524-1
IBM API Connect<=V10.0.8.0 - V10.0.8.9
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/vimto a version that resolves this vulnerability.Fixed in 2:9.2.0524-1 - Upgrade
Upgrade
Vim (zip.vim)to a version that resolves this vulnerability.Fixed in 9.2.0280
Event History
Apr 6, 2026
CVE Published
via MITRE·05:54 PM
Data Sourced
via MITRE·05:54 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·06:16 PM
DescriptionSeverityWeaknessAffected Software
Data Sourced
via Red Hat·07:01 PM
DescriptionSeverityAffected Software
Apr 8, 2026
Data Sourced
via Microsoft·08:01 AM
DescriptionSeverityWeaknessAffected Software
Updated
via Microsoft·08:01 AM
DescriptionSeverity
Jul 2, 2026
Data Sourced
via Debian·07:19 PM
DescriptionAffected Software
Data Sourced
via Launchpad·07:20 PM
Description
Jul 3, 2026
Data Sourced
via Ubuntu·07:19 PM
RemedyDescriptionSeverityAffected Software
Jul 7, 2026
Data Sourced
via IBM·12:00 AM
DescriptionAffected Software