logo

Claude AI Discovers Zero-Day RCE Vulnerabilities in Vim and Emacs

ID: db5e9c97-e514-58cf-af9c-b59888586781

STIX ID: report--db5e9c97-e514-58cf-af9c-b59888586781

Feed Name: cybersecurityNews.com

Threat Score
70/100

Date Published: 2026-03-31

Date Updated: 2026-05-05

Author: Guru Baran

...
...

Anthropic's Claude AI discovered and produced proofs-of-concept for zero-day RCEs in two popular text editors: Vim (RCE via opening a crafted .md file; patched under GHSA-2gmj-rpqf-pxvh — upgrade to v9.2.0172) and GNU Emacs (RCE via extracting/opening a file from an archive; currently unpatched with maintainers attributing the root cause to Git). The researchers announced a "MAD Bugs: Month of AI-Discovered Bugs" campaign to publish additional AI-found vulnerabilities.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.