PT-2025-51976 · Zed · Zed

Aaronportnoy

·

Published

2025-12-17

·

Updated

2025-12-20

·

CVE-2025-68433

CVSS v3.1

7.7

High

VectorAV:L/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Zed versions prior to 0.218.2-pre
Description The Zed IDE is susceptible to arbitrary code execution through maliciously crafted Model Context Protocol (MCP) configurations. These configurations, found in the settings.json file within a project’s .zed subdirectory, can contain arbitrary shell commands. These commands execute on the host system with the privileges of the user running the IDE, potentially triggered automatically upon opening a project. The vulnerability stems from the IDE loading MCP configurations without proper validation.
Recommendations Versions prior to 0.218.2-pre should be updated to version 0.218.2-pre or later. Carefully review the contents of project settings files (./zed/settings.json) before opening new projects in Zed.

Exploit

Fix

Command Injection

Weakness Enumeration

Related Identifiers

CVE-2025-68433
GHSA-CV6G-CMXC-VW8J

Affected Products

Zed