top of page
perceptive_background_267k.jpg

Zed is a code editor. Prior to 0.227.1, Zed builds SSH/WSL remote commands as a shell command string that starts with exec env ..., but environment variable key…

Published:

27 May 2026 at 22:00:00

Alert date:

28 May 2026 at 18:03:14

Source:

nvd.nist.gov

Click to open the original link from this advisory

Web Technologies, Security Tools

CVE-2026-44461 affects Zed code editor versions prior to 0.227.1. The vulnerability allows arbitrary command execution on remote hosts through shell command injection in environment variable keys. When Zed builds SSH/WSL remote commands, environment variable keys are inserted without proper shell quoting or validation. Attackers who can control environment variable keys can exploit shell expansions to execute arbitrary commands on the remote host under the victim's account. The vulnerability is triggered when opening a terminal in the affected environment. This issue has been fixed in version 0.227.1.

Technical details

Mitigation steps:

Affected products:

Zed

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Disclaimer: Deze website toont informatie afkomstig van externe bronnen. Perceptive aanvaardt geen verantwoordelijkheid voor de inhoud, juistheid of volledigheid van deze informatie.

bottom of page