


Perceptive Security
SOC/SIEM Consultancy

Zed is a code editor. Prior to 0.227.1, Zed builds SSH/WSL remote commands as a shell command string that starts with exec env ..., but environment variable key…
Published:
27 May 2026 at 22:00:00
Alert date:
28 May 2026 at 18:03:14
Source:
nvd.nist.gov
Web Technologies, Security Tools
CVE-2026-44461 affects Zed code editor versions prior to 0.227.1. The vulnerability allows arbitrary command execution on remote hosts through shell command injection in environment variable keys. When Zed builds SSH/WSL remote commands, environment variable keys are inserted without proper shell quoting or validation. Attackers who can control environment variable keys can exploit shell expansions to execute arbitrary commands on the remote host under the victim's account. The vulnerability is triggered when opening a terminal in the affected environment. This issue has been fixed in version 0.227.1.
Technical details
Mitigation steps:
Affected products:
Zed
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-44461
https://github.com/zed-industries/zed/security/advisories/GHSA-63qj-jc2q-7hg5
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
