


Perceptive Security
SOC/SIEM Consultancy

Zed is a code editor. Prior to 0.227.1, Zed IDE executes arbitrary commands when opening a folder with a malicious .git/config file that abuses the core.fsmonit…
Published:
27 mei 2026 om 22:00:00
Alert date:
28 mei 2026 om 19:09:38
Source:
nvd.nist.gov
Security Tools, Supply Chain & Dependencies
A critical vulnerability in Zed code editor prior to version 0.227.1 allows remote code execution through malicious .git/config files. The vulnerability abuses the core.fsmonitor Git configuration option to execute arbitrary commands when a victim opens a folder in untrusted mode. This represents a significant security risk for developers using the Zed IDE. The vulnerability has been patched in version 0.227.1. Users should update immediately to prevent potential exploitation.
Technical details
Mitigation steps:
Affected products:
Zed IDE
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-44465
https://github.com/zed-industries/zed/security/advisories/GHSA-fj2r-rmw6-h222
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
