cvedb.io
CVE-2025-55157
HIGH · CVSS 8.8
EPSS exploitation probability: 0%
Published 2025-08-11T23:15:27.870 · Last modified 2026-06-17T09:41:22.320

Summary

Vim is an open source, command line text editor. In versions from 9.1.1231 to before 9.1.1400, When processing nested tuples in Vim script, an error during evaluation can trigger a use-after-free in Vim’s internal tuple reference management. Specifically, the tuple_unref() function may access already freed memory due to improper lifetime handling, leading to memory corruption. The exploit requires direct user interaction, as the script must be explicitly executed within Vim. This issue has been patched in version 9.1.1400.

Affected products

vim — vim

Does this affect you?

Add your gear to cvedb and we'll alert you only when vim ships something exploited.

Check my exposure →

References

This product uses data from the NVD API but is not endorsed or certified by the NVD. Informational only; not professional security advice.