zed records
11 published records for vendor zed.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 1
- With a fix record
- 45.5%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')4
- CWE-77 Improper Neutralization of Special Elements used in a Command ('Command Injection')2
- CWE-356 Product UI does not Warn User of Unsafe Actions1
- CWE-184 Incomplete List of Disallowed Inputs1
- CWE-61 UNIX Symbolic Link (Symlink) Following1
- CWE-59 Improper Link Resolution Before File Access ('Link Following')1
The weakness classes this vendor ships most often: where to look.
CWEAll records
11 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
35Monitor | CVE-2026-27976No exploit | Zed Extension Sandbox Escape via Tar Symlink Followingzed · zed · CWE-61 | High8.8 | — | 0.7% | Feb 25, 2026 |
35Monitor | CVE-2026-44462No exploit | Zed: Allowlist Bypass via Bash Variable Expansion Chain in Terminal Tool Permissionszed · zed · CWE-184 | High8.8 | — | 0.5% | May 28, 2026 |
34Monitor | CVE-2026-44465No exploit | Zed: Zed IDE Arbitrary Code Execution via untrusted repository with poisoned .git/configzed · zed · CWE-78 | High8.6 | — | 0.3% | May 28, 2026 |
34Monitor | CVE-2026-44461No exploit | Zed: Remote Command Injection via Unquoted Environment Variable Keys (SSH / WSL Remote)zed · zed · CWE-78 | High8.6 | — | 0.2% | May 28, 2026 |
34Monitor | CVE-2026-44466No exploit | Zed: Allowlist Bypass via Bash Arithmetic Expansion in Terminal Tool Permissionszed · zed · CWE-78 | High8.6 | — | 0.2% | May 28, 2026 |
32Monitor | CVE-2026-25805No exploit | Zed does not show Parameter Values for MCP Tool Calls. Users cannot detect tool poisoning.zed · zed · CWE-356 | High8.0 | — | 0.4% | Feb 10, 2026 |
31Monitor | CVE-2026-44463No exploit | Zed: Allowlist Bypass via Environment Variable Injection in Terminal Tool Permissionszed · zed · CWE-78 | High7.8 | — | 0.2% | May 28, 2026 |
29Monitor | CVE-2026-27800No exploit | Zed has Zip Slip Path Traversal in Extension Archive Extractionzed · zed · CWE-22 | High7.4 | — | 0.4% | Feb 25, 2026 |
29Monitor | CVE-2025-68433No exploit | Zed IDE MCP Context Server Configuration Arbitrary Code Executionzed · zed · CWE-77 | High7.3 | — | 0.3% | Dec 17, 2025 |
29Monitor | CVE-2025-68432No exploit | Zed IDE LSP Binary Configuration Arbitrary Code Executionzed · zed · CWE-77 | High7.3 | — | 0.3% | Dec 17, 2025 |
28Monitor | CVE-2026-27967No exploit | Symlink Escape in Agent File Toolszed · zed · CWE-59 | High7.1 | — | 0.2% | Feb 25, 2026 |
- CVE-2026-2797635Monitor
Zed Extension Sandbox Escape via Tar Symlink Following
HighCVSS 8.8No exploitEPSS 1%zed · zedFeb 25, 2026
- CVE-2026-4446235Monitor
Zed: Allowlist Bypass via Bash Variable Expansion Chain in Terminal Tool Permissions
HighCVSS 8.8No exploitEPSS 0%zed · zedMay 28, 2026
- CVE-2026-4446534Monitor
Zed: Zed IDE Arbitrary Code Execution via untrusted repository with poisoned .git/config
HighCVSS 8.6No exploitEPSS 0%zed · zedMay 28, 2026
- CVE-2026-4446134Monitor
Zed: Remote Command Injection via Unquoted Environment Variable Keys (SSH / WSL Remote)
HighCVSS 8.6No exploitEPSS 0%zed · zedMay 28, 2026
- CVE-2026-4446634Monitor
Zed: Allowlist Bypass via Bash Arithmetic Expansion in Terminal Tool Permissions
HighCVSS 8.6No exploitEPSS 0%zed · zedMay 28, 2026
- CVE-2026-2580532Monitor
Zed does not show Parameter Values for MCP Tool Calls. Users cannot detect tool poisoning.
HighCVSS 8.0No exploitEPSS 0%zed · zedFeb 10, 2026
- CVE-2026-4446331Monitor
Zed: Allowlist Bypass via Environment Variable Injection in Terminal Tool Permissions
HighCVSS 7.8No exploitEPSS 0%zed · zedMay 28, 2026
- CVE-2026-2780029Monitor
Zed has Zip Slip Path Traversal in Extension Archive Extraction
HighCVSS 7.4No exploitEPSS 0%zed · zedFeb 25, 2026
- CVE-2025-6843329Monitor
Zed IDE MCP Context Server Configuration Arbitrary Code Execution
HighCVSS 7.3No exploitEPSS 0%zed · zedDec 17, 2025
- CVE-2025-6843229Monitor
Zed IDE LSP Binary Configuration Arbitrary Code Execution
HighCVSS 7.3No exploitEPSS 0%zed · zedDec 17, 2025
- CVE-2026-2796728Monitor
Symlink Escape in Agent File Tools
HighCVSS 7.1No exploitEPSS 0%zed · zedFeb 25, 2026