CVE-2026-44463
PoC —CVSS 3.1
7.8 high
EPSS
<1%p14
Published
()
Modified
Description
Zed is a code editor. Prior to 0.229.0, Zed's terminal tool permission system can be bypassed by prepending environment variable assignments to allowlisted commands, hijacking program behavior (e.g., PAGER) to execute arbitrary code. This vulnerability is fixed in 0.229.0.
- Vendors
- zed
- Products
- zed
- Weakness
- CWE-78, CWE-184
- Vector
- CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.