]> git.ipfire.org Git - thirdparty/vim.git/commit
patch 9.1.1947: [security]: Windows: Vim may execute commands from current directory v9.1.1947
authorChristian Brabandt <cb@256bit.org>
Tue, 25 Nov 2025 21:45:58 +0000 (22:45 +0100)
committerChristian Brabandt <cb@256bit.org>
Tue, 2 Dec 2025 21:22:02 +0000 (21:22 +0000)
commit083ec6d9a3b7b09006e0ce69ac802597d25856d6
treeb4feacba9a18b133ce94877c46fdc66c004acb29
parentc0f2d2f14076c32451edb9622da15d54f4abae73
patch 9.1.1947: [security]: Windows: Vim may execute commands from current directory

Problem:  [security]: Windows: Vim may execute commands from current
          directory (Simon Zuckerbraun)
Solution: Set the $NoDefaultCurrentDirectoryInExePath before running
          external commands.

Github Advisory:
https://github.com/vim/vim/security/advisories/GHSA-g77q-xrww-p834

Signed-off-by: Christian Brabandt <cb@256bit.org>
runtime/doc/builtin.txt
src/os_win32.c
src/testdir/test_terminal2.vim
src/version.c