CVE-2026-44463

Zed is a code editor. Prior to 0.229.0, Zed's terminal tool permission system can be bypassed by prepending environment variable assignments to allowlisted commands, hijacking program behavior (e.g., PAGER) to execute arbitrary code. This vulnerability is fixed in 0.229.0.
Configurations

Configuration 1 (hide)

cpe:2.3:a:zed:zed:*:*:*:*:*:*:*:*

History

03 Jun 2026, 01:11

Type Values Removed Values Added
References () https://github.com/zed-industries/zed/security/advisories/GHSA-c3g6-c3ff-69cg - () https://github.com/zed-industries/zed/security/advisories/GHSA-c3g6-c3ff-69cg - Exploit, Vendor Advisory
First Time Zed zed
Zed
CPE cpe:2.3:a:zed:zed:*:*:*:*:*:*:*:*

28 May 2026, 17:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-05-28 17:16

Updated : 2026-06-03 01:11


NVD link : CVE-2026-44463

Mitre link : CVE-2026-44463

CVE.ORG link : CVE-2026-44463


JSON object : View

Products Affected

zed

  • zed
CWE
CWE-78

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

CWE-184

Incomplete List of Disallowed Inputs