PT-2026-39598 · Zed · Zed

·

CVE-2026-44462

·

Published

2026-05-11

·

Updated

2026-06-03

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Zed versions prior to 0.229.0
Description The terminal tool permission system in the Zed code editor can be bypassed using bash variable expansion chaining (${var@P}). This allows for arbitrary command execution when an allowlisted command prefix is used.
Recommendations Update to version 0.229.0.

Exploit

Fix

Incomplete List of Disallowed Inputs

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-44462
GHSA-RQQ3-P6X4-Q866

Affected Products

Zed