PT-2026-22049 · Zed · Zed

Yueyuel

·

Published

2026-02-25

·

Updated

2026-03-05

·

CVE-2026-27967

CVSS v3.1

7.1

High

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Zed versions prior to 0.225.9
Description A symlink escape issue exists in Zed, a code editor, within the Agent file tools (read file, edit file). This allows reading and writing files outside the project directory when the project contains symbolic links pointing to external paths. This bypasses workspace boundaries and privacy protections (file scan exclusions, private files), potentially exposing sensitive user data to the LLM. The issue allows bypassing the intended workspace boundary and privacy protections.
Recommendations Update to version 0.225.9 or later.

Exploit

Fix

Link Following

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-27967
GHSA-786M-X2VC-5235

Affected Products

Zed