On 3/30/26 05:06, Christian Brabandt wrote:
> ## Impact
> An attacker who can deliver a crafted file to a victim achieves 
> arbitrary command execution with the privileges of the user running Vim. 
> The attack requires only that the victim opens the file; no further 
> interaction is needed. `modeline` is enabled by default and 
> `modelineexpr` does not need to be enabled. Vim builds with `+tabpanel` 
> (FEAT_HUGE, the default) are affected.

Should `modeline` be disabled by default in future releases?
It's a huge attack surface.
-- 
Sincerely,
Demi Marie Obenour (she/her/hers)

Attachment: OpenPGP_0xB288B55FFF9C22C1.asc
Description: OpenPGP public key

Attachment: OpenPGP_signature.asc
Description: OpenPGP digital signature

Reply via email to