Vim, a text editor, is vulnerable to potential data loss with zip.vim and special crafted zip files in versions prior to 9.1.1198. The impact is medium because a user must be made to view such an archive with Vim and then press 'x' on such a strange filename. The issue has been fixed as of Vim patch v9.1.1198.
{
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/29xxx/CVE-2025-29768.json",
"cna_assigner": "GitHub_M",
"cwe_ids": [
"CWE-88"
]
}[
{
"source": "https://github.com/vim/vim/commit/f209dcd3defb95bae21b2740910e6aa7bb940531",
"id": "CVE-2025-29768-b8d41b9d",
"target": {
"file": "src/version.c"
},
"digest": {
"line_hashes": [
"146200493773228420153804765641940418619",
"47028650726253441014203008513030660914",
"83048208654470333696592244285775702330",
"137128912601977820449335824883705228029"
],
"threshold": 0.9
},
"deprecated": false,
"signature_version": "v1",
"signature_type": "Line"
}
]