git/list[1] front-page[2] threads[3] people[4] search[5] about
 

CVE-2025-66476

From
LALuis Alvarado <luis.alvarado.torres@gmail.com>
Date
Jan 22, 2026, 16:40 UTC
Message-ID
<CALFwtBbK6sNo0swy5k_+jgcKQmOpw3b=o8_UKhvLhtYYLqoUow@mail.gmail.com>
Hello!

I need some help or guidance on how to remediate this vulnerability. We have a customer with Git, which includes VIM and is vulnerable to CVE-2025-66476. However, the GIT version for Windows was last updated in November 2025. How can I remediate this issue, is there a way to update VIM without updating git? if so , how.

File C:\Program Files\Git\usr\bin\vim.exe&; version &#96;9.1.1914&#96; is vulnerable to &#96;CVE-2025-66476&#96;, which exists in versions &#96;&lt; 9.1.1947&#96;.

Thank you!

-- Luis A. Alvarado, M.S., CISSP, CEH, (ISC)² CAP, Security+ | IT Specialist (INFOSEC) This e-mail message and any attachment(s) are intended only for use by the addressee(s) named herein and may contain legally privileged and/or confidential information. If you are not the intended recipient of this e-mail message, you are hereby notified that any dissemination, distribution, or copying of this e-mail message, including any attachment(s), is strictly prohibited. If you have received this e-mail message in error, please immediately notify me by telephone or e-mail and permanently delete or destroy the original and any copy (electronic or printout) of this e-mail message, including any attachment(s).

... Truth is the only safe ground to stand on. - Anonymous
Next: Junio C Hamano
Message 1 of 2 in “CVE-2025-66476”
  1. Luis AlvaradoJan 22, 2026
  2. Junio C HamanoJan 22, 2026

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.