CVE-2026-27976
- EPSS 0.1%
- Veröffentlicht 25.02.2026 23:34:40
- Zuletzt bearbeitet 05.03.2026 16:08:38
Zed, a code editor, has an extension installer allows tar/gzip downloads. Prior to version 0.224.4, the tar extractor (`async_tar::Archive::unpack`) creates symlinks from the archive without validation, and the path guard (`writeable_path_from_extens...
CVE-2026-27967
- EPSS 0.01%
- Veröffentlicht 25.02.2026 23:33:21
- Zuletzt bearbeitet 05.03.2026 16:10:10
Zed, a code editor, has a symlink escape vulnerability in versions prior to 0.225.9 in Agent file tools (`read_file`, `edit_file`). It allows reading and writing files **outside the project directory** when a project contains symbolic links pointing ...
CVE-2026-27800
- EPSS 0.04%
- Veröffentlicht 25.02.2026 23:25:45
- Zuletzt bearbeitet 04.03.2026 03:16:37
Zed, a code editor, has a Zip Slip (Path Traversal) vulnerability exists in its extension archive extraction functionality prior to version 0.224.4. The `extract_zip()` function in `crates/util/src/archive.rs` fails to validate ZIP entry filenames fo...
- EPSS 0.06%
- Veröffentlicht 10.02.2026 17:27:49
- Zuletzt bearbeitet 19.02.2026 15:08:32
Zed is a multiplayer code editor. Prior to 0.219.4, Zed does not show with which parameters a tool is being invoked, when asking for allowance. Further it does not show after the tool was being invoked, which parameters were used. Thus, maybe unwante...
CVE-2025-68433
- EPSS 0.03%
- Veröffentlicht 17.12.2025 22:47:40
- Zuletzt bearbeitet 19.02.2026 15:05:59
Zed, a code editor, has an aribtrary code execution vulnerability in versions prior to 0.218.2-pre. The Zed IDE loads Model Context Protocol (MCP) configurations from the `settings.json` file located within a project’s `.zed` subdirectory. A maliciou...
CVE-2025-68432
- EPSS 0.03%
- Veröffentlicht 17.12.2025 22:45:42
- Zuletzt bearbeitet 19.02.2026 15:10:51
Zed, a code editor, has an aribtrary code execution vulnerability in versions prior to 0.218.2-pre. The Zed IDE loads Language Server Protocol (LSP) configurations from the `settings.json` file located within a project’s `.zed` subdirectory. A malici...