Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2019-12735

48
FAUCET Score

CVE-2019-12735 is a critical arbitrary OS command execution vulnerability affecting Vim before version 8.1.1365 and Neovim before version 0.3.6. This flaw allows remote attackers to execute arbitrary commands through the :source! command within a modeline. With a CVSS score of 8.6 (High), the vulnerability has a low attack complexity and requires user interaction, but can lead to complete compromise of confidentiality, integrity, and availability. While not listed on CISA KEV and showing no active exploitation or community discussion, public exploit code is available on ExploitDB, indicating a potential for future attacks.

Impacted Technologies

VendorProductVersion(s)CPE
< 8.1.1365CPE matchmatch criteria
cpe:2.3:a:vim:vim:*:*:*:*:*:*:*:*
< 0.3.6CPE matchmatch criteria
cpe:2.3:a:neovim:neovim:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.0

8.6HIGH

CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H

Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
REQUIRED
Scope
CHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
Exploitability Score
1.8
Impact Score
6.0
CvssVersion
3.0

Exploit Intelligence

EPSS Score
19.11%
Probability of exploitation in next 30 days
EPSS Percentile
97.0%
Percentile rank of EPSS score among Peer Group
As of 2026-07-25
Model: v2026.06.15
ExploitDB: EDB-46973 · Jun 4, 2019
This CVE's current EPSS score of 0.1911 is in the 97th percentile among its peer group of 11,616 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (10)

github_advisorypatch availablevia nvd_reference
View patch
microsoftpatch availablevia msrc
Product: 17000-16820Fixed in: 8.1.0388-7
microsoftpatch availablevia msrc
Product: CBL Mariner 1.0 ARMFixed in: 8.1.0388-7
microsoftpatch availablevia msrc
Product: cm1 vim 8.1.0388-7 on CBL Mariner 1.0Fixed in: 8.1.0388-7
microsoftpatch availablevia msrc
Product: CBL Mariner 1.0 x64Fixed in: 8.1.0388-7
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 7.5 Extended Update SupportFixed in: vim-2:7.4.160-4.el7_5.1
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: vim-2:8.0.1763-11.el8_0
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 6Fixed in: vim-2:7.4.629-5.el6_10.2
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 7Fixed in: vim-2:7.4.160-6.el7_6
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 7.4 Extended Update SupportFixed in: vim-2:7.4.160-2.el7_4.1
View patch

Vendor Advisories (3)

microsoft2020-Sep/CVE-2019-12735

CVE-2019-12735

Sep 8, 2020
microsoft2019-Jun/CVE-2019-12735Important

getchar.c in Vim before 8.1.1365 and Neovim before 0.3.6 allows remote attackers to execute arbitrary OS commands via the :source! command in a modeline as demonstrated by execute in Vim and assert_fails or nvim_input in Neovim.

Jun 11, 2019
redhatCVE-2019-12735Important

vim/neovim: ': source!' command allows arbitrary command execution via modelines

Jun 5, 2019

References

lists.fedoraproject.org / archives/list/package-announce%40lists.fedoraproject.org/message/2BMDSHTF754TITC6AQJPCS5IRIDMMIM7
lists.fedoraproject.org / archives/list/package-announce%40lists.fedoraproject.org/message/TRIRBC2YRGKPAWVRMZS4SZTGGCVRVZPR
support.f5.com / csp/article/K93144355
lists.opensuse.org / opensuse-security-announce/2019-06/msg00031.html
lists.opensuse.org / opensuse-security-announce/2019-06/msg00036.html
lists.opensuse.org / opensuse-security-announce/2019-06/msg00037.html
lists.opensuse.org / opensuse-security-announce/2019-07/msg00034.html
lists.opensuse.org / opensuse-security-announce/2019-07/msg00050.html
lists.opensuse.org / opensuse-security-announce/2019-08/msg00075.html
access.redhat.com / errata/RHSA-2019:1619
access.redhat.com / errata/RHSA-2019:1774
access.redhat.com / errata/RHSA-2019:1793
access.redhat.com / errata/RHSA-2019:1947
bugs.debian.org / 930020
Mailing ListThird Party Advisory
bugs.debian.org / 930024
Mailing ListThird Party Advisory
github.com / neovim/neovim/pull/10082
PatchThird Party Advisory
github.com / numirias/security/blob/master/doc/2019-06-04_ace-vim-neovim.md
ExploitPatchThird Party Advisory
github.com / vim/vim/commit/53575521406739cf20bbe4e384d88e7dca11f040
PatchThird Party Advisory
lists.debian.org / debian-lts-announce/2019/08/msg00003.html
lists.fedoraproject.org / archives/list/[email protected]/message/2BMDSHTF754TITC6AQJPCS5IRIDMMIM7
lists.fedoraproject.org / archives/list/[email protected]/message/TRIRBC2YRGKPAWVRMZS4SZTGGCVRVZPR
seclists.org / bugtraq/2019/Jul/39
seclists.org / bugtraq/2019/Jun/33
security.gentoo.org / glsa/202003-04
support.f5.com / csp/article/K93144355
support.f5.com / csp/article/K93144355
usn.ubuntu.com / 4016-1
usn.ubuntu.com / 4016-2
debian.org / security/2019/dsa-4467
debian.org / security/2019/dsa-4487
exploit-db.com / exploits/46973
securityfocus.com / bid/108724