{"id":27183,"date":"2019-06-12T18:53:16","date_gmt":"2019-06-12T18:53:16","guid":{"rendered":"https:\/\/www.threatshub.org\/blog\/this-is-grim-vim-and-neovim-opening-this-crafty-file-in-your-editor-may-pwn-your-box-patch-now-if-not-already\/"},"modified":"2019-06-12T18:53:16","modified_gmt":"2019-06-12T18:53:16","slug":"this-is-grim-vim-and-neovim-opening-this-crafty-file-in-your-editor-may-pwn-your-box-patch-now-if-not-already","status":"publish","type":"post","link":"https:\/\/www.threatshub.org\/blog\/this-is-grim-vim-and-neovim-opening-this-crafty-file-in-your-editor-may-pwn-your-box-patch-now-if-not-already\/","title":{"rendered":"This is grim, Vim and Neovim: Opening this crafty file in your editor may pwn your box. Patch now if not already"},"content":{"rendered":"<div><img decoding=\"async\" src=\"https:\/\/regmedia.co.uk\/2017\/04\/20\/sad_penguin_photo_via_shutterstock.jpg\" class=\"ff-og-image-inserted\"><\/div>\n<p>Proof-of-concept text files are now available that, when opened in a vulnerable installation of the Vim and Neovim, will execute commands on the underlying machine, or even open a backdoor.<\/p>\n<p>Bug-hunter Armin Razmjou <a target=\"_blank\" rel=\"nofollow noopener noreferrer\" href=\"https:\/\/github.com\/numirias\/security\/blob\/master\/doc\/2019-06-04_ace-vim-neovim.md\">this week documented<\/a> a security hole, designated CVE-2019-12735, in the popular text and source code editors that can be potentially exploited by malicious documents to commandeer victims&#8217; computers when opened. The vulnerability is present in Vim versions prior to 8.1.1365, and Neovim builds before 0.3.6.<\/p>\n<p>Razmjou reported the issue to the maintainers of both applications on May 22. Vim had a patch out by May 23, and Neovim released its fix on May 29. Now that Razmjou&#8217;s exploit code is available, you should ensure you&#8217;re patched: updating either application to the most recent build will address the flaw. Razmjou also noted that some Linux distributions, such as Debian, ship with Vim configuration files that block the hole by default \u2013 more on that below.<\/p>\n<h3 class=\"crosshead\"><span>Invader Vim<\/span><\/h3>\n<p>The infosec bod said the vulnerability lies in code that handles modeline instructions that Vim uses to set things like the text width or spacing in a file. These settings are usually specified within a given text file to format it as needed, however, it turns out these modelines can be abused to execute system commands on the underlying host as the user.<\/p>\n<p>&#8220;The modeline feature allows to specify custom editor options near the start or end of a file,&#8221; Razmjou explained. &#8220;This feature is enabled by default and applies to all file types, including plain .txt.&#8221;<\/p>\n<p>Normally, the modeline settings are limited to a small group of functions, and any system command to be executed is isolated in a sandbox to keep it from harming or accessing the rest of the computer.<\/p>\n<p>That sandbox, however, can be turned off by putting a modifier (in this case <code>!<\/code>) at the end of a source instruction. This instruction reads in a specific file from the file system, or the file being edited if <code>%<\/code> is used. Combining <code>!<\/code> and <code>%<\/code> makes Vim execute commands within the edited text file outside the sandbox.<\/p>\n<p>Ramzjou&#8217;s proof-of-concept text file demonstrates how this can be exploited to open a backdoor, known as a reverse shell, allowing miscreants to inject system commands over the network or internet, and cover its tracks after.<\/p>\n<p>In another example, see below, the text runs the command <code>uname -a<\/code> on the underlying box to get details of the operating system kernel.<\/p>\n<pre>\n:!uname -a||\" vi:fen:fdm=expr:fde=assert_fails(\"source\\!\\ \\%\"):fdl=0:fdt=\"\n<\/pre>\n<p>Save that as <code>poc.txt<\/code> and then run <code>vim poc.txt<\/code> as normal to trigger the flaw.<\/p>\n<p>In addition to updating Vim and Neovim to the latest versions, there are other protections you can put in place to avoid attack. Your .vimrc configuration file in your home directory can be modified to disable modelines (include <code>set nomodeline<\/code>), or you can disable expressions in modelines (<code>modelineexpr<\/code>) completely.<\/p>\n<p>With Debian and some other Linux distros, the .vimrc ships with modelines already disabled by default, hence those versions are not vulnerable out of the box, though it is still a good idea to update your copy of Vim or Neovim to the latest version. \u00ae<\/p>\n<p>READ MORE <a href=\"http:\/\/go.theregister.com\/feed\/www.theregister.co.uk\/2019\/06\/12\/vim_remote_command_execution_flaw\/\">HERE<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Welcome to Vim Sh*tty 2000 Proof-of-concept text files are now available that, when opened in a vulnerable installation of the Vim and Neovim, will execute commands on the underlying machine, or even open a backdoor.\u2026 READ MORE HERE&#8230;<\/p>\n","protected":false},"author":2,"featured_media":27184,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"colormag_page_layout":"default_layout","footnotes":""},"categories":[63],"tags":[],"class_list":["post-27183","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-the-register"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v28.1 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>This is grim, Vim and Neovim: Opening this crafty file in your editor may pwn your box. Patch now if not already 2026 | ThreatsHub Cybersecurity News<\/title>\n<meta name=\"description\" content=\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security &amp; Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.threatshub.org\/blog\/this-is-grim-vim-and-neovim-opening-this-crafty-file-in-your-editor-may-pwn-your-box-patch-now-if-not-already\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"This is grim, Vim and Neovim: Opening this crafty file in your editor may pwn your box. Patch now if not already 2026 | ThreatsHub Cybersecurity News\" \/>\n<meta property=\"og:description\" content=\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security &amp; Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.threatshub.org\/blog\/this-is-grim-vim-and-neovim-opening-this-crafty-file-in-your-editor-may-pwn-your-box-patch-now-if-not-already\/\" \/>\n<meta property=\"og:site_name\" content=\"ThreatsHub Cybersecurity News\" \/>\n<meta property=\"article:published_time\" content=\"2019-06-12T18:53:16+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2019\/06\/this-is-grim-vim-and-neovim-opening-this-crafty-file-in-your-editor-may-pwn-your-box-patch-now-if-not-already.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"648\" \/>\n\t<meta property=\"og:image:height\" content=\"432\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"TH Author\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@threatshub\" \/>\n<meta name=\"twitter:site\" content=\"@threatshub\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"TH Author\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"3 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/this-is-grim-vim-and-neovim-opening-this-crafty-file-in-your-editor-may-pwn-your-box-patch-now-if-not-already\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/this-is-grim-vim-and-neovim-opening-this-crafty-file-in-your-editor-may-pwn-your-box-patch-now-if-not-already\\\/\"},\"author\":{\"name\":\"TH Author\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/person\\\/12e0a8671ff89a863584f193e7062476\"},\"headline\":\"This is grim, Vim and Neovim: Opening this crafty file in your editor may pwn your box. Patch now if not already\",\"datePublished\":\"2019-06-12T18:53:16+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/this-is-grim-vim-and-neovim-opening-this-crafty-file-in-your-editor-may-pwn-your-box-patch-now-if-not-already\\\/\"},\"wordCount\":529,\"publisher\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/this-is-grim-vim-and-neovim-opening-this-crafty-file-in-your-editor-may-pwn-your-box-patch-now-if-not-already\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2019\\\/06\\\/this-is-grim-vim-and-neovim-opening-this-crafty-file-in-your-editor-may-pwn-your-box-patch-now-if-not-already.jpg\",\"articleSection\":[\"The Register\"],\"inLanguage\":\"en-US\"},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/this-is-grim-vim-and-neovim-opening-this-crafty-file-in-your-editor-may-pwn-your-box-patch-now-if-not-already\\\/\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/this-is-grim-vim-and-neovim-opening-this-crafty-file-in-your-editor-may-pwn-your-box-patch-now-if-not-already\\\/\",\"name\":\"This is grim, Vim and Neovim: Opening this crafty file in your editor may pwn your box. Patch now if not already 2026 | ThreatsHub Cybersecurity News\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/this-is-grim-vim-and-neovim-opening-this-crafty-file-in-your-editor-may-pwn-your-box-patch-now-if-not-already\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/this-is-grim-vim-and-neovim-opening-this-crafty-file-in-your-editor-may-pwn-your-box-patch-now-if-not-already\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2019\\\/06\\\/this-is-grim-vim-and-neovim-opening-this-crafty-file-in-your-editor-may-pwn-your-box-patch-now-if-not-already.jpg\",\"datePublished\":\"2019-06-12T18:53:16+00:00\",\"description\":\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/this-is-grim-vim-and-neovim-opening-this-crafty-file-in-your-editor-may-pwn-your-box-patch-now-if-not-already\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/this-is-grim-vim-and-neovim-opening-this-crafty-file-in-your-editor-may-pwn-your-box-patch-now-if-not-already\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/this-is-grim-vim-and-neovim-opening-this-crafty-file-in-your-editor-may-pwn-your-box-patch-now-if-not-already\\\/#primaryimage\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2019\\\/06\\\/this-is-grim-vim-and-neovim-opening-this-crafty-file-in-your-editor-may-pwn-your-box-patch-now-if-not-already.jpg\",\"contentUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2019\\\/06\\\/this-is-grim-vim-and-neovim-opening-this-crafty-file-in-your-editor-may-pwn-your-box-patch-now-if-not-already.jpg\",\"width\":648,\"height\":432},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/this-is-grim-vim-and-neovim-opening-this-crafty-file-in-your-editor-may-pwn-your-box-patch-now-if-not-already\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"This is grim, Vim and Neovim: Opening this crafty file in your editor may pwn your box. Patch now if not already\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#website\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\",\"name\":\"ThreatsHub Cybersecurity News\",\"description\":\"%%focuskw%% Threat Intel \u2013 Threat Intel Services \u2013 CyberIntelligence \u2013 Cyber Threat Intelligence - Threat Intelligence Feeds - Threat Intelligence Reports - CyberSecurity Report \u2013 Cyber Security PDF \u2013 Cybersecurity Trends - Cloud Sandbox \u2013- Threat IntelligencePortal \u2013 Incident Response \u2013 Threat Hunting \u2013 IOC - Yara - Security Operations Center \u2013 SecurityOperation Center \u2013 Security SOC \u2013 SOC Services - Advanced Threat - Threat Detection - TargetedAttack \u2013 APT \u2013 Anti-APT \u2013 Advanced Protection \u2013 Cyber Security Services \u2013 Cybersecurity Services -Threat Intelligence Platform\",\"publisher\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\"},\"alternateName\":\"Threatshub.org\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\",\"name\":\"ThreatsHub.org\",\"alternateName\":\"Threatshub.org\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/05\\\/Threatshub_Favicon1.jpg\",\"contentUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/05\\\/Threatshub_Favicon1.jpg\",\"width\":432,\"height\":435,\"caption\":\"ThreatsHub.org\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\"},\"sameAs\":[\"https:\\\/\\\/x.com\\\/threatshub\"]},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/person\\\/12e0a8671ff89a863584f193e7062476\",\"name\":\"TH Author\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"caption\":\"TH Author\"}}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"This is grim, Vim and Neovim: Opening this crafty file in your editor may pwn your box. Patch now if not already 2026 | ThreatsHub Cybersecurity News","description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.threatshub.org\/blog\/this-is-grim-vim-and-neovim-opening-this-crafty-file-in-your-editor-may-pwn-your-box-patch-now-if-not-already\/","og_locale":"en_US","og_type":"article","og_title":"This is grim, Vim and Neovim: Opening this crafty file in your editor may pwn your box. Patch now if not already 2026 | ThreatsHub Cybersecurity News","og_description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","og_url":"https:\/\/www.threatshub.org\/blog\/this-is-grim-vim-and-neovim-opening-this-crafty-file-in-your-editor-may-pwn-your-box-patch-now-if-not-already\/","og_site_name":"ThreatsHub Cybersecurity News","article_published_time":"2019-06-12T18:53:16+00:00","og_image":[{"width":648,"height":432,"url":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2019\/06\/this-is-grim-vim-and-neovim-opening-this-crafty-file-in-your-editor-may-pwn-your-box-patch-now-if-not-already.jpg","type":"image\/jpeg"}],"author":"TH Author","twitter_card":"summary_large_image","twitter_creator":"@threatshub","twitter_site":"@threatshub","twitter_misc":{"Written by":"TH Author","Est. reading time":"3 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.threatshub.org\/blog\/this-is-grim-vim-and-neovim-opening-this-crafty-file-in-your-editor-may-pwn-your-box-patch-now-if-not-already\/#article","isPartOf":{"@id":"https:\/\/www.threatshub.org\/blog\/this-is-grim-vim-and-neovim-opening-this-crafty-file-in-your-editor-may-pwn-your-box-patch-now-if-not-already\/"},"author":{"name":"TH Author","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/person\/12e0a8671ff89a863584f193e7062476"},"headline":"This is grim, Vim and Neovim: Opening this crafty file in your editor may pwn your box. Patch now if not already","datePublished":"2019-06-12T18:53:16+00:00","mainEntityOfPage":{"@id":"https:\/\/www.threatshub.org\/blog\/this-is-grim-vim-and-neovim-opening-this-crafty-file-in-your-editor-may-pwn-your-box-patch-now-if-not-already\/"},"wordCount":529,"publisher":{"@id":"https:\/\/www.threatshub.org\/blog\/#organization"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/this-is-grim-vim-and-neovim-opening-this-crafty-file-in-your-editor-may-pwn-your-box-patch-now-if-not-already\/#primaryimage"},"thumbnailUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2019\/06\/this-is-grim-vim-and-neovim-opening-this-crafty-file-in-your-editor-may-pwn-your-box-patch-now-if-not-already.jpg","articleSection":["The Register"],"inLanguage":"en-US"},{"@type":"WebPage","@id":"https:\/\/www.threatshub.org\/blog\/this-is-grim-vim-and-neovim-opening-this-crafty-file-in-your-editor-may-pwn-your-box-patch-now-if-not-already\/","url":"https:\/\/www.threatshub.org\/blog\/this-is-grim-vim-and-neovim-opening-this-crafty-file-in-your-editor-may-pwn-your-box-patch-now-if-not-already\/","name":"This is grim, Vim and Neovim: Opening this crafty file in your editor may pwn your box. Patch now if not already 2026 | ThreatsHub Cybersecurity News","isPartOf":{"@id":"https:\/\/www.threatshub.org\/blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.threatshub.org\/blog\/this-is-grim-vim-and-neovim-opening-this-crafty-file-in-your-editor-may-pwn-your-box-patch-now-if-not-already\/#primaryimage"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/this-is-grim-vim-and-neovim-opening-this-crafty-file-in-your-editor-may-pwn-your-box-patch-now-if-not-already\/#primaryimage"},"thumbnailUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2019\/06\/this-is-grim-vim-and-neovim-opening-this-crafty-file-in-your-editor-may-pwn-your-box-patch-now-if-not-already.jpg","datePublished":"2019-06-12T18:53:16+00:00","description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","breadcrumb":{"@id":"https:\/\/www.threatshub.org\/blog\/this-is-grim-vim-and-neovim-opening-this-crafty-file-in-your-editor-may-pwn-your-box-patch-now-if-not-already\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.threatshub.org\/blog\/this-is-grim-vim-and-neovim-opening-this-crafty-file-in-your-editor-may-pwn-your-box-patch-now-if-not-already\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.threatshub.org\/blog\/this-is-grim-vim-and-neovim-opening-this-crafty-file-in-your-editor-may-pwn-your-box-patch-now-if-not-already\/#primaryimage","url":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2019\/06\/this-is-grim-vim-and-neovim-opening-this-crafty-file-in-your-editor-may-pwn-your-box-patch-now-if-not-already.jpg","contentUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2019\/06\/this-is-grim-vim-and-neovim-opening-this-crafty-file-in-your-editor-may-pwn-your-box-patch-now-if-not-already.jpg","width":648,"height":432},{"@type":"BreadcrumbList","@id":"https:\/\/www.threatshub.org\/blog\/this-is-grim-vim-and-neovim-opening-this-crafty-file-in-your-editor-may-pwn-your-box-patch-now-if-not-already\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.threatshub.org\/blog\/"},{"@type":"ListItem","position":2,"name":"This is grim, Vim and Neovim: Opening this crafty file in your editor may pwn your box. Patch now if not already"}]},{"@type":"WebSite","@id":"https:\/\/www.threatshub.org\/blog\/#website","url":"https:\/\/www.threatshub.org\/blog\/","name":"ThreatsHub Cybersecurity News","description":"%%focuskw%% Threat Intel \u2013 Threat Intel Services \u2013 CyberIntelligence \u2013 Cyber Threat Intelligence - Threat Intelligence Feeds - Threat Intelligence Reports - CyberSecurity Report \u2013 Cyber Security PDF \u2013 Cybersecurity Trends - Cloud Sandbox \u2013- Threat IntelligencePortal \u2013 Incident Response \u2013 Threat Hunting \u2013 IOC - Yara - Security Operations Center \u2013 SecurityOperation Center \u2013 Security SOC \u2013 SOC Services - Advanced Threat - Threat Detection - TargetedAttack \u2013 APT \u2013 Anti-APT \u2013 Advanced Protection \u2013 Cyber Security Services \u2013 Cybersecurity Services -Threat Intelligence Platform","publisher":{"@id":"https:\/\/www.threatshub.org\/blog\/#organization"},"alternateName":"Threatshub.org","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.threatshub.org\/blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/www.threatshub.org\/blog\/#organization","name":"ThreatsHub.org","alternateName":"Threatshub.org","url":"https:\/\/www.threatshub.org\/blog\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/logo\/image\/","url":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2025\/05\/Threatshub_Favicon1.jpg","contentUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2025\/05\/Threatshub_Favicon1.jpg","width":432,"height":435,"caption":"ThreatsHub.org"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/x.com\/threatshub"]},{"@type":"Person","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/person\/12e0a8671ff89a863584f193e7062476","name":"TH Author","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","caption":"TH Author"}}]}},"_links":{"self":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts\/27183","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/comments?post=27183"}],"version-history":[{"count":0,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts\/27183\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/media\/27184"}],"wp:attachment":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/media?parent=27183"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/categories?post=27183"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/tags?post=27183"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}