logo

Claude AI finds Vim, Emacs RCE bugs that trigger on file open

ID: e7ee5ee7-bbc1-5357-86d6-ef5d1af16754

STIX ID: report--e7ee5ee7-bbc1-5357-86d6-ef5d1af16754

Feed Name: Bleeping Computer

Threat Score
70/100

Date Published: 2026-03-31

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

**Executive summary:** The report details RCE vulnerabilities in widely used text editors: a modeline-based arbitrary command execution bug in Vim (patched in 9.2.0272) and an unpatched Emacs vector where vc-git causes Git to read and execute attacker-controlled core.fsmonitor settings from a .git/config, allowing payload execution when a user opens a crafted file or archive; users should avoid opening untrusted files and apply available patches or mitigations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.