PT-2026-7326 · Zed · Zed
M10X
·
Publicado
2026-02-10
·
Atualizado
2026-02-10
·
CVE-2026-25805
CVSS v3.1
8.0
Alta
| Vetor | AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Zed versions prior to 0.219.4
Description
Zed, a multiplayer code editor, does not display the parameters used when invoking a tool, both during the allowance request and after invocation. This lack of visibility could allow the use of unwanted or malicious values without the user’s knowledge. The issue concerns tool call details and the potential for tool poisoning.
Recommendations
Update to version 0.219.4 or later to benefit from expandable tool call details.
Exploit
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Zed