


Perceptive Security
SOC/SIEM Consultancy

Zed is a code editor. Prior to 0.227.1, Zed builds SSH/WSL remote commands as a shell command string that starts with exec env ..., but environment variable key…
Published:
27 mei 2026 om 22:00:00
Alert date:
28 mei 2026 om 19:09:38
Source:
nvd.nist.gov
Security Tools
CVE-2026-44461 affects Zed code editor versions prior to 0.227.1. The vulnerability occurs when Zed builds SSH/WSL remote commands using shell command strings starting with 'exec env', but fails to properly validate or quote environment variable keys. Attackers who can control environment variable keys through project terminal settings can inject shell expansions like $(...) that get evaluated by the remote shell when terminals are opened. This leads to arbitrary command execution on remote hosts under the victim's user account. The vulnerability is fixed in version 0.227.1.
Technical details
Mitigation steps:
Affected products:
Zed
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-44461
https://github.com/zed-industries/zed/security/advisories/GHSA-63qj-jc2q-7hg5
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
