CVE-2019-20807: Apple Mac OS X
Medium severity, CVSS 5.3. EPSS: 0.5% chance of exploitation in the next 30 days.
In Vim before 8.1.0881, users can circumvent the rvim restricted mode and execute arbitrary OS commands via scripting interfaces (e.g., Python, Ruby, or Lua).
Affected products
- Apple Mac OS X: version 10.13.6 only; version 10.14.6 only
- Canonical Ubuntu Linux: version 16.04 only; version 18.04 only
- Debian Debian Linux: version 9.0 only
- Opensuse Leap: version 15.1 only
- Starwindsoftware Command Center: version 2 only
- Starwindsoftware San & NAS: version 1.0 only
- Vim Vim: before 8.1.0881 (fixed in 8.1.0881)
Published 2020-05-28. Last modified 2026-06-17.