{"id":"CVE-2023-4736","title":"Untrusted Search Path in GitHub repository vim/vim prior to 9.0.1833.","summary":"Untrusted Search Path in GitHub repository vim/vim prior to 9.0.1833.","severity":"high","cvss":7.8,"cvssVector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","cwe":["CWE-426"],"vendor":"vim","product":"vim","affected":["vim < 9.0.1833","macos = 14.0"],"patched":["vim 9.0.1833"],"published":"2023-09-02","updated":"2026-06-23","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2023-4736","references":[{"url":"http://seclists.org/fulldisclosure/2023/Oct/24","label":"security@huntr.dev"},{"url":"https://github.com/vim/vim/commit/816fbcc262687b81fc46f82f7bbeb1453addfe0c","label":"security@huntr.dev"},{"url":"https://huntr.dev/bounties/e1ce0995-4df4-4dec-9cd7-3136ac3e8e71","label":"security@huntr.dev"},{"url":"https://support.apple.com/kb/HT213984","label":"security@huntr.dev"},{"url":"http://seclists.org/fulldisclosure/2023/Oct/24","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://github.com/vim/vim/commit/816fbcc262687b81fc46f82f7bbeb1453addfe0c","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://huntr.dev/bounties/e1ce0995-4df4-4dec-9cd7-3136ac3e8e71","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://support.apple.com/kb/HT213984","label":"af854a3a-2127-422b-91ae-364da2661108"}],"tags":["nvd"],"epss":0.00513,"epssPercentile":0.42552,"ingestedAt":"2026-06-29T13:24:33.881Z","slug":"CVE-2023-4736","body":"## Overview\n\nUntrusted Search Path in GitHub repository vim/vim prior to 9.0.1833.\n\n## Affected\n\n- `vim < 9.0.1833`\n- `macos = 14.0`\n\n## Remediation\n\nUpgrade past the affected range:\n\n- `vim 9.0.1833`","depth":"twilight","depthScore":43,"depthScoreParts":{"impact":42.9,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}