top of page
perceptive_background_267k.jpg

Zed is a code editor. Prior to 0.227.1, Zed IDE executes arbitrary commands when opening a folder with a malicious .git/config file that abuses the core.fsmonit…

Published:

27 May 2026 at 22:00:00

Alert date:

28 May 2026 at 18:03:14

Source:

nvd.nist.gov

Click to open the original link from this advisory

Security Tools

Zed code editor prior to version 0.227.1 contains a critical vulnerability that allows remote code execution when opening folders with malicious .git/config files. The vulnerability exploits the core.fsmonitor Git configuration option to execute arbitrary commands when a victim opens a folder in untrusted mode. This represents a significant security risk for developers using the Zed IDE as it could allow attackers to compromise systems through seemingly innocent project folders containing crafted Git configuration files.

Technical details

Mitigation steps:

Affected products:

Zed IDE

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Disclaimer: Deze website toont informatie afkomstig van externe bronnen. Perceptive aanvaardt geen verantwoordelijkheid voor de inhoud, juistheid of volledigheid van deze informatie.

bottom of page