Zed is a focused developer tool vendor centered on a single code editor product that has gained prominence in the developer tooling landscape. The vulnerability footprint concentrates in command-injection and path-traversal weaknesses—issues that arise from the product's interaction with operating-system processes and file handling—alongside incomplete input validation in path-based operations. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Zed over time
Signals from CVEs in this vendor scope (11 CVEs).
11 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-44466HIGH Zed is a code editor. Prior to 0.229.0, Zed's terminal tool permission system can be bypassed via bash arithmetic expansion $((...)), allowing execution of arbitrary commands neste | May 28, 2026 | 8.6 | 32 | NO | NO |
CVE-2026-44465HIGH Zed is a code editor. Prior to 0.227.1, Zed IDE executes arbitrary commands when opening a folder with a malicious .git/config file that abuses the core.fsmonitor Git configuration | May 28, 2026 | 8.6 | 32 | NO | NO |
CVE-2026-44461HIGH Zed is a code editor. Prior to 0.227.1, Zed builds SSH/WSL remote commands as a shell command string that starts with exec env ..., but environment variable keys are inserted witho | May 28, 2026 | 8.6 | 32 | NO | NO |
CVE-2026-44463HIGH Zed is a code editor. Prior to 0.229.0, Zed's terminal tool permission system can be bypassed by prepending environment variable assignments to allowlisted commands, hijacking prog | May 28, 2026 | 7.8 | 30 | NO | NO |
CVE-2026-27976HIGH Zed, a code editor, has an extension installer allows tar/gzip downloads. Prior to version 0.224.4, the tar extractor (`async_tar::Archive::unpack`) creates symlinks from the archi | Feb 26, 2026 | 8.8 | 30 | NO | NO |
CVE-2026-44462HIGH Zed is a code editor. Prior to 0.229.0, Zed's terminal tool permission system can be bypassed via bash variable expansion chaining (${var@P}), allowing arbitrary command execution | May 28, 2026 | 8.8 | 29 | NO | NO |
CVE-2026-25805HIGH Zed is a multiplayer code editor. Prior to 0.219.4, Zed does not show with which parameters a tool is being invoked, when asking for allowance. Further it does not show after the t | Feb 10, 2026 | 8.0 | 25 | NO | NO |
CVE-2025-68433HIGH Zed, a code editor, has an aribtrary code execution vulnerability in versions prior to 0.218.2-pre. The Zed IDE loads Model Context Protocol (MCP) configurations from the `settings | Dec 17, 2025 | 7.3 | 25 | NO | NO |
CVE-2025-68432HIGH Zed, a code editor, has an aribtrary code execution vulnerability in versions prior to 0.218.2-pre. The Zed IDE loads Language Server Protocol (LSP) configurations from the `settin | Dec 17, 2025 | 7.3 | 25 | NO | NO |
CVE-2026-27967HIGH Zed, a code editor, has a symlink escape vulnerability in versions prior to 0.225.9 in Agent file tools (`read_file`, `edit_file`). It allows reading and writing files **outside th | Feb 26, 2026 | 7.1 | 24 | NO | NO |
Signals from CVEs in this vendor scope (11 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Zed.
Media articles that mention a CVE ID that affects a product developed by Zed — matched by CVE ID, not by vendor name.