CVE-2019-14957: JetBrains Vim
Medium severity, CVSS 5.3. EPSS: 1.1% chance of exploitation in the next 30 days.
The JetBrains Vim plugin before version 0.52 was storing individual project data in the global vim_settings.xml file. This xml file could be synchronized to a publicly accessible GitHub repository.
Affected products
- JetBrains Vim: before 0.52 (fixed in 0.52)
Published 2019-10-01. Last modified 2026-06-17.