Zed

Zed

11 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.23%
  • Veröffentlicht 28.05.2026 16:16:05
  • Zuletzt bearbeitet 02.06.2026 20:14:36

Zed is a code editor. Prior to 0.229.0, Zed's terminal tool permission system can be bypassed via bash arithmetic expansion $((...)), allowing execution of arbitrary commands nested inside an allowlisted command like echo. This vulnerability is fixed...

Exploit
  • EPSS 0.23%
  • Veröffentlicht 28.05.2026 16:15:13
  • Zuletzt bearbeitet 03.06.2026 01:11:27

Zed is a code editor. Prior to 0.229.0, Zed's terminal tool permission system can be bypassed by prepending environment variable assignments to allowlisted commands, hijacking program behavior (e.g., PAGER) to execute arbitrary code. This vulnerabili...

Exploit
  • EPSS 0.44%
  • Veröffentlicht 28.05.2026 16:13:49
  • Zuletzt bearbeitet 03.06.2026 01:00:02

Zed is a code editor. Prior to 0.229.0, Zed's terminal tool permission system can be bypassed via bash variable expansion chaining (${var@P}), allowing arbitrary command execution under an allowlisted command prefix. This vulnerability is fixed in 0....

Exploit
  • EPSS 0.3%
  • Veröffentlicht 28.05.2026 16:10:58
  • Zuletzt bearbeitet 02.06.2026 20:17:42

Zed is a code editor. Prior to 0.227.1, Zed IDE executes arbitrary commands when opening a folder with a malicious .git/config file that abuses the core.fsmonitor Git configuration option. This allows an attacker to achieve Remote Code Execution (RCE...

Exploit
  • EPSS 0.26%
  • Veröffentlicht 28.05.2026 16:08:07
  • Zuletzt bearbeitet 03.06.2026 00:58:30

Zed is a code editor. Prior to 0.227.1, Zed builds SSH/WSL remote commands as a shell command string that starts with exec env ..., but environment variable keys are inserted without shell quoting or validation. If an attacker can control an environm...

Exploit
  • EPSS 0.49%
  • Veröffentlicht 25.02.2026 23:34:40
  • Zuletzt bearbeitet 05.03.2026 16:08:38

Zed, a code editor, has an extension installer allows tar/gzip downloads. Prior to version 0.224.4, the tar extractor (`async_tar::Archive::unpack`) creates symlinks from the archive without validation, and the path guard (`writeable_path_from_extens...

Exploit
  • EPSS 0.24%
  • Veröffentlicht 25.02.2026 23:33:21
  • Zuletzt bearbeitet 05.03.2026 16:10:10

Zed, a code editor, has a symlink escape vulnerability in versions prior to 0.225.9 in Agent file tools (`read_file`, `edit_file`). It allows reading and writing files **outside the project directory** when a project contains symbolic links pointing ...

Exploit
  • EPSS 0.29%
  • Veröffentlicht 25.02.2026 23:25:45
  • Zuletzt bearbeitet 04.03.2026 03:16:37

Zed, a code editor, has a Zip Slip (Path Traversal) vulnerability exists in its extension archive extraction functionality prior to version 0.224.4. The `extract_zip()` function in `crates/util/src/archive.rs` fails to validate ZIP entry filenames fo...

Exploit
  • EPSS 0.24%
  • Veröffentlicht 10.02.2026 17:27:49
  • Zuletzt bearbeitet 19.02.2026 15:08:32

Zed is a multiplayer code editor. Prior to 0.219.4, Zed does not show with which parameters a tool is being invoked, when asking for allowance. Further it does not show after the tool was being invoked, which parameters were used. Thus, maybe unwante...

Exploit
  • EPSS 0.25%
  • Veröffentlicht 17.12.2025 22:47:40
  • Zuletzt bearbeitet 19.02.2026 15:05:59

Zed, a code editor, has an aribtrary code execution vulnerability in versions prior to 0.218.2-pre. The Zed IDE loads Model Context Protocol (MCP) configurations from the `settings.json` file located within a project’s `.zed` subdirectory. A maliciou...