PT-2026-22049 · Zed · Zed
Yueyuel
·
Publicado
2026-02-25
·
Atualizado
2026-03-05
·
CVE-2026-27967
CVSS v3.1
7.1
Alta
| Vetor | AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
Zed versions prior to 0.225.9
Description
A symlink escape issue exists in Zed, a code editor, within the Agent file tools (
read file, edit file). This allows reading and writing files outside the project directory when the project contains symbolic links pointing to external paths. This bypasses workspace boundaries and privacy protections (file scan exclusions, private files), potentially exposing sensitive user data to the LLM. The issue allows bypassing the intended workspace boundary and privacy protections.Recommendations
Update to version 0.225.9 or later.
Exploit
Correção
Link Following
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Zed