Zed is a code editor. Prior to 0.229.0, Zed's terminal tool permission system can be bypassed by prepending environment variable assignments to allowlisted commands, hijacking program behavior (e.g., PAGER) to execute arbitrary code. This vulnerability is fixed in 0.229.0.
Metrics
Affected Vendors & Products
References
History
Thu, 28 May 2026 18:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Zed-industries
Zed-industries zed |
|
| Vendors & Products |
Zed-industries
Zed-industries zed |
Thu, 28 May 2026 17:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Zed is a code editor. Prior to 0.229.0, Zed's terminal tool permission system can be bypassed by prepending environment variable assignments to allowlisted commands, hijacking program behavior (e.g., PAGER) to execute arbitrary code. This vulnerability is fixed in 0.229.0. | |
| Title | Zed: Allowlist Bypass via Environment Variable Injection in Terminal Tool Permissions | |
| Weaknesses | CWE-184 CWE-78 |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-05-28T16:15:13.826Z
Reserved: 2026-05-06T15:49:25.193Z
Link: CVE-2026-44463
No data.
Status : Received
Published: 2026-05-28T17:16:29.810
Modified: 2026-05-28T17:16:29.810
Link: CVE-2026-44463
No data.
OpenCVE Enrichment
Updated: 2026-05-28T18:30:23Z