


Perceptive Security
SOC/SIEM Consultancy

Zed is a code editor. Prior to 0.229.0, Zed's terminal tool permission system can be bypassed by prepending environment variable assignments to allowlisted comm…
Published:
27 May 2026 at 22:00:00
Alert date:
28 May 2026 at 18:03:14
Source:
nvd.nist.gov
Security Tools
Zed code editor contains a vulnerability in versions prior to 0.229.0 where the terminal tool permission system can be bypassed. Attackers can prepend environment variable assignments to allowlisted commands to hijack program behavior. The vulnerability allows execution of arbitrary code by manipulating environment variables like PAGER. This represents a significant security flaw that could allow unauthorized code execution in the development environment. The issue has been fixed in version 0.229.0.
Technical details
Mitigation steps:
Affected products:
Zed
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-44463
https://github.com/zed-industries/zed/security/advisories/GHSA-c3g6-c3ff-69cg
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
