On 3/30/26 05:06, Christian Brabandt wrote: > ## Impact > An attacker who can deliver a crafted file to a victim achieves > arbitrary command execution with the privileges of the user running Vim. > The attack requires only that the victim opens the file; no further > interaction is needed. `modeline` is enabled by default and > `modelineexpr` does not need to be enabled. Vim builds with `+tabpanel` > (FEAT_HUGE, the default) are affected.
Should `modeline` be disabled by default in future releases? It's a huge attack surface. -- Sincerely, Demi Marie Obenour (she/her/hers)
OpenPGP_0xB288B55FFF9C22C1.asc
Description: OpenPGP public key
OpenPGP_signature.asc
Description: OpenPGP digital signature
