PT-2026-44411 · Zed · Zed

·

CVE-2026-44461

·

Published

2026-05-28

·

Updated

2026-06-03

CVSS v3.1

8.6

High

VectorAV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Zed versions prior to 0.227.1
Description Zed builds SSH/WSL remote commands as a shell command string starting with exec env ..., where environment variable keys are inserted without shell quoting or validation. An attacker who can control an environment variable key, such as through project terminal settings, can trigger shell expansions (e.g., $(...)) that are evaluated by the remote shell when a terminal is opened. This allows for arbitrary command execution on the remote host under the victim user's account.
Recommendations Update to version 0.227.1.

Exploit

Fix

RCE

OS Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-44461
GHSA-63QJ-JC2Q-7HG5

Affected Products

Zed