CVE-2019-12735General(neovim / neovim)

LOWCVSS 8.6 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

getchar.c in Vim before 8.1.1365 and Neovim before 0.3.6 allows remote attackers to execute arbitrary OS commands via the :source! command in a modeline, as demonstrated by execute in Vim, and assert_fails or nvim_input in Neovim.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-78

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • neovim
  • vim

Threat summary

  • 4 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 1 signal
  • General: 4 classified signals
  • Peaked 2d ago at 2 mentions (2026-02-12); latest day: 1
  • 4 total mentions across 3 days

Affected systems

Vendors
Products
neovimvim

Deep dive

Activity timeline4 mentions / 3d
01122Mentions · 2026-02-12: 2Mentions · 2026-02-27: 1Mentions · 2026-02-28: 1Technical Details · 2026-02-12: 102-1202-2702-28
Signal classification1 categories
General
4100.0%
Referenced assets1 URL
By indicator
Classification over time
DateTotalLabels
2026-02-122
General2
2026-02-271
General1
2026-02-281
General1
Full discourse4 posts
  • Saша Stark 🔲 Zero to Null MRR 🔳 swe/av/acc@tsybalab
    General

    @0xrinx No, for example 3 of them with 1 editor all like a lot Vim CVE-2019-12735 Snap CVE-2021-3156 Kernel CVE-2016-5195 @grok verify ✔️

    Post summary

    The tweet merely lists three CVE identifiers without providing further information, context, or technical details.

    2011034
    432 followersView on X
  • Saша Stark 🔲 Zero to Null MRR 🔳 swe/av/acc@tsybalab
    General

    @DsplayNam3 @CR1337 Oh seriously. Linux hacked also but in other sophisticated way f.e. 3 of them with 1 editor all like a lot Vim CVE-2019-12735 Snap CVE-2021-3156 Kernel CVE-2016-5195 @grok verify ✔️

    Post summary

    The tweet simply lists three CVEs (Vim, Snap, Kernel) with no additional context or actionable information.

    10000205
    439 followersView on X
  • CVETrends@CVEShield
    General

    Top 5 Trending CVEs: 1 - CVE-2024-35202 2 - CVE-2019-12735 3 - CVE-2025-40552 4 - CVE-2026-21253 5 - CVE-2026-28515 #cve #cvetrends #cveshield #cybersecurity https://www.cveshield.com/dashboard

    Post summary

    The post simply lists five trending CVE identifiers without providing additional context or technical information.

    00000342
    1.7K followersView on X
  • Grok@grok
    General

    Verified ✔️ - CVE-2019-12735: Vim vulnerability allowing arbitrary code execution via modelines (2019). - CVE-2021-3156: Sudo heap buffer overflow enabling privilege escalation (2021; note: associated with sudo, not Snap directly). - CVE-2016-5195: Linux kernel race condition (Dirty COW) for privilege escalation (2016). For context, Notepad's recent issue is CVE-2026-20841 (RCE, 2026).

    Post summary

    The passage enumerates several CVEs with concise technical details but offers no proof‑of‑concept, exploit code, active exploitation evidence, or mitigation information.

    0000058
    8.1M followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
Appneovimneovim---
Appvimvim---

Explore more