Vim Has A 0-Day????
Unlock all features
FREE: Get instant access to 10 AI summaries, chats, or transcripts per day.
Unlock all features
FREE: Get instant access to 10 AI summaries, chats, or transcripts per day.
Unlock all features
FREE: Get instant access to 10 AI summaries, chats, or transcripts per day.
Unlock all features
FREE: Get instant access to 10 AI summaries, chats, or transcripts per day.
Unlock all features
FREE: Get instant access to 10 AI summaries, chats, or transcripts per day.
Related videos
Haskell is DONE
The PrimeTime
135.1k views
I was right again
The PrimeTime
166.7k views
4 words triggered a war
The PrimeTime
150.4k views
You Owe Him
The PrimeTime
71.0k views
Why Did They Build This?
The PrimeTime
126.3k views
This CEO is Crazy
The PrimeTime
52.8k views
Zig is at a crossroads
The PrimeTime
120.3k views
"I suck" -ThePrimeagen
The PrimeTime
55.8k views
It's all fake
The PrimeTime
88.9k views
Linus Lays down the Law
The PrimeTime
118.5k views
Top Comments (10)
Good thing I haven’t been able to close vim since 2010. I’m still running vim 7.3 on the same terminal I opened my first hello world
jarvis, find me 0-day RCEs >Ok, here's 2 documented features
Everyone freaking out meanwhile people are still piping curl straight into bash
I checked my default vim configuration on Mac and not only is Modeline disabled, the config contains a comment referencing CVE-2007-2438 for the same issue. Truly a revolutionary find by Claude.
This is why i'm using punchcards
Finds bug where remote code can be executed by a built-in part of the system that executes code.
"We found a RCE in Emacs!" proceed to show a weird git feature
5:19 "They might be able to hack 25 people." Shots fired.
I might be showing my age here but we knew way back in the early 2000s that modelines were a bad idea, are unsafe and that every sane person has it disabled. But also no one wanted to fix this because some people are relying on this. Problem for Vim was that afaik until Vim8 modelines were still enabled by default and might still be? I only remember that Vim8 was the great breaking point to make saner default options. So it's not really a new bug or a zero day. We knew for literally decades. That's like saying "we found that using Xorg network server is unsafe and can be easily exploited" or "if you leave your front door open people can just walk in".
Bro found an alternative way to execute the exploit just so he doesn’t have to install emacs
Unlock the Data Inside
Turn Videos into Knowledge
- Get FREE 10/day: transcripts, summaries, chats
- Chat with videos, export text & PDF
- $1 free API credit for RAG, chatbots & research
Free forever plan • All features unlocked
Top Comments (10)
Good thing I haven’t been able to close vim since 2010. I’m still running vim 7.3 on the same terminal I opened my first hello world
jarvis, find me 0-day RCEs >Ok, here's 2 documented features
Everyone freaking out meanwhile people are still piping curl straight into bash
I checked my default vim configuration on Mac and not only is Modeline disabled, the config contains a comment referencing CVE-2007-2438 for the same issue. Truly a revolutionary find by Claude.
This is why i'm using punchcards
Finds bug where remote code can be executed by a built-in part of the system that executes code.
"We found a RCE in Emacs!" proceed to show a weird git feature
5:19 "They might be able to hack 25 people." Shots fired.
I might be showing my age here but we knew way back in the early 2000s that modelines were a bad idea, are unsafe and that every sane person has it disabled. But also no one wanted to fix this because some people are relying on this. Problem for Vim was that afaik until Vim8 modelines were still enabled by default and might still be? I only remember that Vim8 was the great breaking point to make saner default options. So it's not really a new bug or a zero day. We knew for literally decades. That's like saying "we found that using Xorg network server is unsafe and can be easily exploited" or "if you leave your front door open people can just walk in".
Bro found an alternative way to execute the exploit just so he doesn’t have to install emacs