Hi James, > Version: 0.12.3-1 > > On Sun, Jun 14, 2026 at 03:47:54PM +0200, Salvatore Bonaccorso wrote: > > CVE-2026-11487[0]: > > | A flaw has been found in Neovim up to 0.12.2. Affected by this issue > > | is the function M.read of the file runtime/lua/vim/secure.lua of the > > | component View Branch. > > This was fixed in 0.12.3-1 already. I'll add a retroactive reference in > the changelog.
Thanks, indeed I did check against the 0.12.2 version but used the wrong version to fill the bugreport. Sorry about the extra work, I just fixed the metadata for the security-tracker. Regards, Salvatore

