Hello GHSA-2gmj-rpqf-pxvh mentions affected versions as < 9.2.0172, although since tabpanel was introduced in 9.1.1391 (https://github.com/vim/vim/commit/be5bd4d6292fddcc103091407792730aaa48cc48), the advisory should mention > 9.1.1391 and < 9.2.0172.
Tabpanel is a relatively new feature and a generic statement "vim < 9.2.0172 has code execution vulnerability" is misleading. -- -- You received this message from the "vim_dev" maillist. Do not top-post! Type your reply below the text you are replying to. For more information, visit http://www.vim.org/maillist.php --- You received this message because you are subscribed to the Google Groups "vim_dev" group. To unsubscribe from this group and stop receiving emails from it, send an email to [email protected]. To view this discussion visit https://groups.google.com/d/msgid/vim_dev/0b565038-eed6-4830-88b0-67e8c7a5aa55n%40googlegroups.com.
