{"id":"CVE-2017-1000212","aliases":[],"url":"https://o3.security/vulnerability/CVE-2017-1000212","summary":"alchemist.vim vulnerable to remote code execution","details":"Elixir's vim plugin, alchemist.vim is vulnerable to remote code execution in the bundled alchemist-server. A malicious website can execute requests against an ephemeral port on localhost that are then evaluated as elixir code.","published":"2022-05-13T01:41:00Z","modified":"2025-12-10T00:32:18.340233Z","cvss":{"score":9.8,"severity":"CRITICAL","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Hex","name":"alchemist.vim","fixedVersion":"1.3.2"}],"fix":{"url":"https://github.com/tonini/alchemist-server/pull/16","label":"tonini/alchemist-server#16"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2017-1000212"},{"type":"WEB","url":"https://github.com/tonini/alchemist-server/issues/14"},{"type":"WEB","url":"https://github.com/tonini/alchemist-server/pull/16"},{"type":"WEB","url":"https://elixirforum.com/t/static-and-session-security-fixes-for-plug/3913"},{"type":"WEB","url":"https://github.com/tonini/alchemist-server"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2025-12-10T00:32:18.340233Z"}}