Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2019-12735-VIM-NEOVIM — Proof-of-concept exploit for CVE-2019-12735 demonstrating arbitrary command execution via Vim/Neovim modeline feature. Includes shellcode injection and reverse shell payload generation for educational security testing. | Kitploit
Tools/GitHubGitHub/oldthree3/cve-2019-12735-vim-neovim
Payload GenerationVulnerability AnalysisExploitationShellcodeLearning & EducationBinary Exploitation
GitHuboldthree3/cve-2019-12735-vim-neovim

CVE-2019-12735-VIM-NEOVIM

Proof-of-concept exploit for CVE-2019-12735 demonstrating arbitrary command execution via Vim/Neovim modeline feature. Includes shellcode injection and reverse shell payload generation for educational security testing.

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
View Repository
2187 years agoNot yet reviewed
Share

CVE-2019-12735-VIM-NEOVIM

USAGE:

Prerequisite: modeline feature must be enabled.
For regular users, modeline is enabled by default, while for root users it is disabled by default.
Use echo &modeline to check the status: 1 means enabled, 0 means disabled.
If not, you can add set modeline to ~/.vimrc (create the file if it does not exist).

When writing manually, note that the escape character x1b is a non-printable character.
To modify the second part of the exploit code, a simple method is to download the source file and modify the command execution part. Alternatively, you can write or modify it using a binary editor.

poc.txt:

vim poc.txt

shell.txt:

nc -lvp 9999

vim shell.txt

then you can get a shell

Security Recommendations

  1. Update vim >= 8.1.1365, neovim > v0.3.6
  2. Add set nomodeline to vimrc to disable modeline.
  3. Do not easily open files from unknown sources.
Download Tool