Home

Description

Zed is a code editor. Prior to 0.229.0, Zed's terminal tool permission system can be bypassed by prepending environment variable assignments to allowlisted commands, hijacking program behavior (e.g., PAGER) to execute arbitrary code. This vulnerability is fixed in 0.229.0.

PUBLISHED Reserved 2026-05-06 | Published 2026-05-28 | Updated 2026-05-29 | Assigner GitHub_M




HIGH: 8.6CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H

Problem types

CWE-184: Incomplete List of Disallowed Inputs

CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

Product status

< 0.229.0
affected

References

github.com/...es/zed/security/advisories/GHSA-c3g6-c3ff-69cg

cve.org (CVE-2026-44463)

nvd.nist.gov (CVE-2026-44463)

Download JSON