{"thread":{"id":"64853","subject":"CVE-2025-66476","startedAt":"2026-01-22T16:40:46Z","lastAt":"2026-01-22T18:09:34Z","messageCount":2,"participants":["Luis Alvarado","Junio C Hamano"],"isPatch":false,"patchVersion":null,"patchTotal":null},"messages":[{"id":"534469","messageId":"CALFwtBbK6sNo0swy5k_+jgcKQmOpw3b=o8_UKhvLhtYYLqoUow@mail.gmail.com","threadId":"64853","inReplyTo":null,"subject":"CVE-2025-66476","fromName":"Luis Alvarado","fromEmail":"luis.alvarado.torres@gmail.com","sentAt":"2026-01-22T16:40:30Z","receivedAt":"2026-01-22T16:40:46Z","isPatch":false,"sender":{"key":"luis.alvarado.torres@gmail.com","avatar":null},"body":"Hello!\n\nI need some help or guidance on how to remediate this vulnerability.\nWe have a customer with Git, which includes VIM and is vulnerable to\nCVE-2025-66476. However, the GIT version for Windows was last updated\nin November 2025. How can I remediate this issue, is there a way to\nupdate VIM without updating git? if so , how.\n\n\nFile C:\\Program Files\\Git\\usr\\bin\\vim.exe&; version &#96;9.1.1914&#96;\nis vulnerable to &#96;CVE-2025-66476&#96;, which exists in versions\n&#96;&lt; 9.1.1947&#96;.\n\n\nThank you!\n\n--\nLuis A. Alvarado, M.S., CISSP, CEH, (ISC)² CAP, Security+ | IT\nSpecialist (INFOSEC)\nThis e-mail message and any attachment(s) are intended only for use by\nthe addressee(s) named herein and may contain legally privileged\nand/or confidential information.  If you are not the intended\nrecipient of this e-mail message, you are hereby notified that any\ndissemination, distribution, or copying of this e-mail message,\nincluding any attachment(s), is strictly prohibited.  If you have\nreceived this e-mail message in error, please immediately notify me by\ntelephone or e-mail and permanently delete or destroy the original and\nany copy (electronic or printout) of this e-mail message, including\nany attachment(s).\n\n... Truth is the only safe ground to stand on. - Anonymous\n"},{"id":"534478","messageId":"xmqqikcto6xy.fsf@gitster.g","threadId":"64853","inReplyTo":"CALFwtBbK6sNo0swy5k_+jgcKQmOpw3b=o8_UKhvLhtYYLqoUow@mail.gmail.com","subject":"Re: CVE-2025-66476","fromName":"Junio C Hamano","fromEmail":"gitster@pobox.com","sentAt":"2026-01-22T18:09:29Z","receivedAt":"2026-01-22T18:09:34Z","isPatch":false,"sender":{"key":"gitster@pobox.com","avatar":"https://avatars.githubusercontent.com/u/54884?v=4"},"body":"Luis Alvarado <luis.alvarado.torres@gmail.com> writes:\n\n> I need some help or guidance on how to remediate this vulnerability.\n> We have a customer with Git, which includes VIM and is vulnerable to\n> CVE-2025-66476. However, the GIT version for Windows was last updated\n> in November 2025. How can I remediate this issue, is there a way to\n> update VIM without updating git? if so , how.\n\nThe Git project does not ship any binary, not even Git binary, let\nalone Vim binary.  We work on and ship only the source code of Git.\n\nIf you are getting your vim as part of the windows port of Git,\nplease redirect your inquiry to the Git for Windows project; you can\nprobably reach out to them at their issue tracker at\n\n    https://github.com/git-for-windows/git/issues.\n\nPlease be sure to search first before asking, since the maintainer\nof the project is busy.\n\nThanks.\n"}]}