Zed IDE Arbitrary Code Execution via untrusted repository with poisoned .git/config
Zed security advisories
All 12 advisories Zed has published with an identifier, newest first. Severity is the one its publisher assigned, and the fix is the release the publisher named. Nothing on this page is our judgement.
- Advisories
- 1212 carry a CVE
- critical
- 1
- high
- 9
- medium
- 2
- Fix in the archive
- 5of 12 matched to a release
- Oldest
- 11 Aug 20251.1 years ago
7 of these point at a version older than anything the archive holds, so there is no release page to link. That is a gap in what was collected, not evidence that the fix does not exist. This page is a copy of what the publisher published, kept for reference. The authoritative source for a security question is the publisher, and an advisory missing from here is not evidence that none exists. What this page does and does not tell you sets out the limits in full.
Newest first
Every productAllowlist Bypass via Bash Arithmetic Expansion in Terminal Tool Permissions
Allowlist Bypass via Bash Variable Expansion Chain in Terminal Tool Permissions
Allowlist Bypass via Environment Variable Injection in Terminal Tool Permissions
Remote Command Injection via Unquoted Environment Variable Keys (SSH / WSL Remote) in Zed v0.225.9
Zip Slip Path Traversal in Extension Archive Extraction
Zed Extension Sandbox Escape via Tar Symlink Following
Symlink Escape in Agent File Tools
Parameter Values are not shown for MCP Tool Calls. Users cannot detect tool poisoning.
Zed IDE MCP Context Server Configuration Arbitrary Code Execution
Zed IDE LSP Binary Configuration Arbitrary Code Execution
AI Agent Remote Code Execution