Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Zed

First CVE: Dec 17, 2025Active for: 1 yearTotal CVEs: 11
49.2
VTI Score
High

Zed is a focused developer tool vendor centered on a single code editor product that has gained prominence in the developer tooling landscape. The vulnerability footprint concentrates in command-injection and path-traversal weaknesses—issues that arise from the product's interaction with operating-system processes and file handling—alongside incomplete input validation in path-based operations. Current severity, exploitation, and exposure counts are shown alongside this summary.

FAUCET AI Generated
11
Total CVEs
More Total CVEs than 92% of tracked vendors
5.5
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 98% of tracked vendors
8.0
Avg CVSS Score
Higher Avg CVSS Score than 78% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Zed over time

Volume of CVEsAvg CVSS Base Score
First CVE
Dec 17, 2025
7 months ago
Most Recent CVE
May 28, 2026
57 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (11 CVEs).

11 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2026-44466HIGH
Zed is a code editor. Prior to 0.229.0, Zed's terminal tool permission system can be bypassed via bash arithmetic expansion $((...)), allowing execution of arbitrary commands neste
May 28, 20268.632NONO
CVE-2026-44465HIGH
Zed is a code editor. Prior to 0.227.1, Zed IDE executes arbitrary commands when opening a folder with a malicious .git/config file that abuses the core.fsmonitor Git configuration
May 28, 20268.632NONO
CVE-2026-44461HIGH
Zed is a code editor. Prior to 0.227.1, Zed builds SSH/WSL remote commands as a shell command string that starts with exec env ..., but environment variable keys are inserted witho
May 28, 20268.632NONO
CVE-2026-44463HIGH
Zed is a code editor. Prior to 0.229.0, Zed's terminal tool permission system can be bypassed by prepending environment variable assignments to allowlisted commands, hijacking prog
May 28, 20267.830NONO
CVE-2026-27976HIGH
Zed, a code editor, has an extension installer allows tar/gzip downloads. Prior to version 0.224.4, the tar extractor (`async_tar::Archive::unpack`) creates symlinks from the archi
Feb 26, 20268.830NONO
CVE-2026-44462HIGH
Zed is a code editor. Prior to 0.229.0, Zed's terminal tool permission system can be bypassed via bash variable expansion chaining (${var@P}), allowing arbitrary command execution
May 28, 20268.829NONO
CVE-2026-25805HIGH
Zed is a multiplayer code editor. Prior to 0.219.4, Zed does not show with which parameters a tool is being invoked, when asking for allowance. Further it does not show after the t
Feb 10, 20268.025NONO
CVE-2025-68433HIGH
Zed, a code editor, has an aribtrary code execution vulnerability in versions prior to 0.218.2-pre. The Zed IDE loads Model Context Protocol (MCP) configurations from the `settings
Dec 17, 20257.325NONO
CVE-2025-68432HIGH
Zed, a code editor, has an aribtrary code execution vulnerability in versions prior to 0.218.2-pre. The Zed IDE loads Language Server Protocol (LSP) configurations from the `settin
Dec 17, 20257.325NONO
CVE-2026-27967HIGH
Zed, a code editor, has a symlink escape vulnerability in versions prior to 0.225.9 in Agent file tools (`read_file`, `edit_file`). It allows reading and writing files **outside th
Feb 26, 20267.124NONO
View all 11 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products11 CVEs
100%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
High
Attack Vector
Local7 (63.6%)
Network4 (36.4%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low11 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None0 (0.0%)
Unknown0 (0.0%)
Required11 (100.0%)
Privileges Required
Low3 (27.3%)
High0 (0.0%)
None8 (72.7%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (11 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Zed.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Zed — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Zed's Products

View all 1 CNAs →

Top CWEs