Zed

Zed

6 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.1%
  • Veröffentlicht 25.02.2026 23:34:40
  • Zuletzt bearbeitet 05.03.2026 16:08:38

Zed, a code editor, has an extension installer allows tar/gzip downloads. Prior to version 0.224.4, the tar extractor (`async_tar::Archive::unpack`) creates symlinks from the archive without validation, and the path guard (`writeable_path_from_extens...

Exploit
  • EPSS 0.01%
  • Veröffentlicht 25.02.2026 23:33:21
  • Zuletzt bearbeitet 05.03.2026 16:10:10

Zed, a code editor, has a symlink escape vulnerability in versions prior to 0.225.9 in Agent file tools (`read_file`, `edit_file`). It allows reading and writing files **outside the project directory** when a project contains symbolic links pointing ...

Exploit
  • EPSS 0.04%
  • Veröffentlicht 25.02.2026 23:25:45
  • Zuletzt bearbeitet 04.03.2026 03:16:37

Zed, a code editor, has a Zip Slip (Path Traversal) vulnerability exists in its extension archive extraction functionality prior to version 0.224.4. The `extract_zip()` function in `crates/util/src/archive.rs` fails to validate ZIP entry filenames fo...

Exploit
  • EPSS 0.06%
  • Veröffentlicht 10.02.2026 17:27:49
  • Zuletzt bearbeitet 19.02.2026 15:08:32

Zed is a multiplayer code editor. Prior to 0.219.4, Zed does not show with which parameters a tool is being invoked, when asking for allowance. Further it does not show after the tool was being invoked, which parameters were used. Thus, maybe unwante...

Exploit
  • EPSS 0.03%
  • Veröffentlicht 17.12.2025 22:47:40
  • Zuletzt bearbeitet 19.02.2026 15:05:59

Zed, a code editor, has an aribtrary code execution vulnerability in versions prior to 0.218.2-pre. The Zed IDE loads Model Context Protocol (MCP) configurations from the `settings.json` file located within a project’s `.zed` subdirectory. A maliciou...

Exploit
  • EPSS 0.03%
  • Veröffentlicht 17.12.2025 22:45:42
  • Zuletzt bearbeitet 19.02.2026 15:10:51

Zed, a code editor, has an aribtrary code execution vulnerability in versions prior to 0.218.2-pre. The Zed IDE loads Language Server Protocol (LSP) configurations from the `settings.json` file located within a project’s `.zed` subdirectory. A malici...