CVE-2019-14957: JetBrains Vim

Medium severity, CVSS 5.3. EPSS: 1.1% chance of exploitation in the next 30 days.

The JetBrains Vim plugin before version 0.52 was storing individual project data in the global vim_settings.xml file. This xml file could be synchronized to a publicly accessible GitHub repository.

Affected products

Published 2019-10-01. Last modified 2026-06-17.