PT-2026-22050 · Zed · Zed
Jayasuryajsk
·
Publicado
2026-02-25
·
Atualizado
2026-03-05
·
CVE-2026-27976
CVSS v3.1
8.8
Alta
| Vetor | AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Zed versions prior to 0.224.4
Description
The extension installer in Zed allows tar/gzip downloads. Prior to version 0.224.4, the tar extractor uses
async tar::Archive::unpack which creates symlinks from the archive without validation. The path guard writeable path from extension performs lexical prefix checks without resolving symlinks. An attacker can ship a tar archive that creates a symlink inside the extension workdir pointing outside, then writes files through the symlink, causing writes to arbitrary host paths. This escapes the extension sandbox and enables code execution.Recommendations
Update to Zed version 0.224.4 or later.
Exploit
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Zed