Zsh is a widely adopted Unix shell that serves as the interactive command interpreter and scripting engine across numerous systems, making vulnerabilities in this core utility a broadly distributed risk. The vendor's vulnerability profile skews strongly toward critical-severity outcomes, concentrating on memory-safety and privilege-handling weaknesses including buffer overflows, improper bounds checking, and unsafe privilege-dropping logic that are characteristic of native C implementations handling untrusted input. Defenders should treat zsh updates as high-priority across all affected systems; current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Zsh over time
Signals from CVEs in this vendor scope (16 CVEs).
16 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-13259CRITICAL An issue was discovered in zsh before 5.6. Shebang lines exceeding 64 characters were truncated, potentially leading to an execve call to a program name that is a substring of the | Sep 5, 2018 | 9.8 | 32 | NO | NO |
CVE-2018-0502CRITICAL An issue was discovered in zsh before 5.6. The beginning of a #! script file was mishandled, potentially leading to an execve call to a program named on the second line. | Sep 5, 2018 | 9.8 | 31 | NO | NO |
CVE-2014-10071CRITICAL In exec.c in zsh before 5.0.7, there is a buffer overflow for very long fds in the ">& fd" syntax. | Feb 27, 2018 | 9.8 | 30 | NO | NO |
CVE-2018-7548CRITICAL In subst.c in zsh through 5.4.2, there is a NULL pointer dereference when using ${(PA)...} on an empty array result. | Feb 27, 2018 | 9.8 | 29 | NO | NO |
CVE-2017-18206CRITICAL In utils.c in zsh before 5.4, symlink expansion had a buffer overflow. | Feb 27, 2018 | 9.8 | 28 | NO | NO |
CVE-2016-10714CRITICAL In zsh before 5.3, an off-by-one error resulted in undersized buffers that were intended to support PATH_MAX characters. | Feb 27, 2018 | 9.8 | 28 | NO | NO |
CVE-2021-45444HIGH In zsh before 5.8.1, an attacker can achieve code execution if they control a command output inside the prompt, as demonstrated by a %F argument. This occurs because of recursive P | Feb 14, 2022 | 7.8 | 27 | NO | NO |
CVE-2019-20044HIGH In Zsh before 5.8, attackers able to execute commands can regain privileges dropped by the --no-PRIVILEGED option. Zsh fails to overwrite the saved uid, so the original privileges | Feb 24, 2020 | 7.8 | 26 | NO | NO |
CVE-2018-1100HIGH zsh through version 5.4.2 is vulnerable to a stack-based buffer overflow in the utils.c:checkmailpath function. A local attacker could exploit this to execute arbitrary code in the | Apr 11, 2018 | 7.8 | 25 | NO | NO |
CVE-2014-10072CRITICAL In utils.c in zsh before 5.0.6, there is a buffer overflow when scanning very long directory paths for symbolic links. | Feb 27, 2018 | 9.8 | 25 | NO | NO |
Signals from CVEs in this vendor scope (16 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Zsh.
Media articles that mention a CVE ID that affects a product developed by Zsh — matched by CVE ID, not by vendor name.