


Perceptive Security
SOC/SIEM Consultancy

Zed is a code editor. Prior to 0.227.1, Zed IDE executes arbitrary commands when opening a folder with a malicious .git/config file that abuses the core.fsmonitā¦
Published:
27 May 2026 at 22:00:00
Alert date:
28 May 2026 at 18:03:14
Source:
nvd.nist.gov
Security Tools
Zed code editor prior to version 0.227.1 contains a critical vulnerability that allows remote code execution when opening folders with malicious .git/config files. The vulnerability exploits the core.fsmonitor Git configuration option to execute arbitrary commands when a victim opens a folder in untrusted mode. This represents a significant security risk for developers using the Zed IDE as it could allow attackers to compromise systems through seemingly innocent project folders containing crafted Git configuration files.
Technical details
Mitigation steps:
Affected products:
Zed IDE
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-44465
https://github.com/zed-industries/zed/security/advisories/GHSA-fj2r-rmw6-h222
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
