PT-2026-22050 · Zed · Zed

Jayasuryajsk

·

Publicado

2026-02-25

·

Atualizado

2026-03-05

·

CVE-2026-27976

CVSS v3.1

8.8

Alta

VetorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Zed versions prior to 0.224.4
Description The extension installer in Zed allows tar/gzip downloads. Prior to version 0.224.4, the tar extractor uses async tar::Archive::unpack which creates symlinks from the archive without validation. The path guard writeable path from extension performs lexical prefix checks without resolving symlinks. An attacker can ship a tar archive that creates a symlink inside the extension workdir pointing outside, then writes files through the symlink, causing writes to arbitrary host paths. This escapes the extension sandbox and enables code execution.
Recommendations Update to Zed version 0.224.4 or later.

Exploit

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2026-27976
GHSA-59P4-3MHM-QM3R

Produtos afetados

Zed