git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: CVE-2025-66476

From
Junio C Hamano <gitster@pobox.com>
Date
Jan 22, 2026, 18:09 UTC
Message-ID
<xmqqikcto6xy.fsf@gitster.g>
In-Reply-To
<CALFwtBbK6sNo0swy5k_+jgcKQmOpw3b=o8_UKhvLhtYYLqoUow@mail.gmail.com>
Luis Alvarado <luis.alvarado.torres@gmail.com> writes:
Show 5 quoted lines
> I need some help or guidance on how to remediate this vulnerability.
> We have a customer with Git, which includes VIM and is vulnerable to
> CVE-2025-66476. However, the GIT version for Windows was last updated
> in November 2025. How can I remediate this issue, is there a way to
> update VIM without updating git? if so , how.

The Git project does not ship any binary, not even Git binary, let alone Vim binary. We work on and ship only the source code of Git.

If you are getting your vim as part of the windows port of Git, please redirect your inquiry to the Git for Windows project; you can probably reach out to them at their issue tracker at

    https://github.com/git-for-windows/git/issues.

Please be sure to search first before asking, since the maintainer of the project is busy.

Thanks.
Previous: Luis Alvarado
Message 2 of 2 in “CVE-2025-66476”
  1. Luis AlvaradoJan 22, 2026
  2. Junio C HamanoJan 22, 2026

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.