


Perceptive Security
SOC/SIEM Consultancy

Zed is a code editor. Prior to 0.229.0, Zed's terminal tool permission system can be bypassed by prepending environment variable assignments to allowlisted comm…
Published:
27 May 2026 at 22:00:00
Alert date:
28 May 2026 at 19:09:38
Source:
nvd.nist.gov
Security Tools
Zed code editor contains a vulnerability in versions prior to 0.229.0 where the terminal tool permission system can be bypassed by prepending environment variable assignments to allowlisted commands. This allows attackers to hijack program behavior through environment variables like PAGER to execute arbitrary code. The vulnerability represents a privilege escalation attack vector that bypasses security controls. The issue has been fixed in version 0.229.0.
Technical details
Mitigation steps:
Affected products:
Zed Code Editor
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-44463
https://github.com/zed-industries/zed/security/advisories/GHSA-c3g6-c3ff-69cg
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
