Google: app-editors/vim, app-editors/vim-core: security update to 18244.521.41

medium Tenable Self-Hosted Container Security Plugin ID 451111

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- Vim is an open source, command line text editor. Prior to version 9.1.1552, a path traversal issue in
Vim’s tar.vim plugin can allow overwriting of arbitrary files when opening specially crafted tar archives.
Impact is low because this exploit requires direct user interaction. However, successfully exploitation
can lead to overwriting sensitive files or placing executable code in privileged locations, depending on
the permissions of the process editing the archive. The victim must edit such a file using Vim which will
reveal the filename and the file content, a careful user may suspect some strange things going on.
Successful exploitation could results in the ability to execute arbitrary commands on the underlying
operating system. Version 9.1.1552 contains a patch for the vulnerability. (CVE-2025-53905)

Solution

Update the app-editors/vim library and its related packages to version 18244.521.41 or later.

See Also

https://storage.googleapis.com/cos-oval-vulnerability-feed/cos-113.oval.xml.tar.gz

Plugin Details

Severity: Medium

ID: 451111

Version: Revision 1.2

Type: Local

Published: 10/1/2026

Updated: 10/2/2026

Supported Sensors: Tenable Cloud Security, Tenable Self-Hosted Container Security

Risk Information

VPR

Risk Factor: Low

Score: 2.3

Percentile: 9.42

Vendor

Vendor Severity: LOW

CVSS v2

Risk Factor: Low

Base Score: 2.6

Temporal Score: 2

Vector: CVSS2#AV:L/AC:H/Au:N/C:N/I:P/A:P

CVSS Score Source: CVE-2025-53905

CVSS v3

Risk Factor: Medium

Base Score: 4.1

Temporal Score: 3.7

Vector: CVSS:3.0/AV:L/AC:H/PR:N/UI:R/S:C/C:N/I:L/A:L

Temporal Vector: CVSS:3.0/E:P/RL:O/RC:C

Vulnerability Information

Exploit Available: true

Exploit Ease: Exploits are available

Reference Information

CVE: CVE-2025-53905