PT-2025-51976 · Zed · Zed
Aaronportnoy
·
Published
2025-12-17
·
Updated
2025-12-20
·
CVE-2025-68433
CVSS v3.1
7.7
High
| Vector | AV:L/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Zed versions prior to 0.218.2-pre
Description
The Zed IDE is susceptible to arbitrary code execution through maliciously crafted Model Context Protocol (MCP) configurations. These configurations, found in the
settings.json file within a project’s .zed subdirectory, can contain arbitrary shell commands. These commands execute on the host system with the privileges of the user running the IDE, potentially triggered automatically upon opening a project. The vulnerability stems from the IDE loading MCP configurations without proper validation.Recommendations
Versions prior to 0.218.2-pre should be updated to version 0.218.2-pre or later.
Carefully review the contents of project settings files (
./zed/settings.json) before opening new projects in Zed.Exploit
Fix
Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Zed