top of page
perceptive_background_267k.jpg

Zed is a code editor. Prior to 0.227.1, Zed builds SSH/WSL remote commands as a shell command string that starts with exec env ..., but environment variable key…

Published:

27 mei 2026 om 22:00:00

Alert date:

28 mei 2026 om 19:09:38

Source:

nvd.nist.gov

Click to open the original link from this advisory

Security Tools

CVE-2026-44461 affects Zed code editor versions prior to 0.227.1. The vulnerability occurs when Zed builds SSH/WSL remote commands using shell command strings starting with 'exec env', but fails to properly validate or quote environment variable keys. Attackers who can control environment variable keys through project terminal settings can inject shell expansions like $(...) that get evaluated by the remote shell when terminals are opened. This leads to arbitrary command execution on remote hosts under the victim's user account. The vulnerability is fixed in version 0.227.1.

Technical details

Mitigation steps:

Affected products:

Zed

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Deze website toont informatie afkomstig van externe bronnen; Perceptive aanvaardt geen verantwoordelijkheid voor de juistheid, volledigheid of actualiteit van deze informatie.

bottom of page