QSearchQSearch

CVE-2026-44461

8.6 HIGH

Zed is a code editor

Published: 2026-05-28 · Last updated: 2026-06-03

Severity and scoring

CVSS
8.6 HIGH
Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
CWE
CWE-78

Affected products

VendorProduct
zedzed

Description

Zed is a code editor. Prior to 0.227.1, Zed builds SSH/WSL remote commands as a shell command string that starts with exec env ..., but environment variable keys are inserted without shell quoting or validation. If an attacker can control an environment variable key (for example via project terminal settings), shell expansions in the key (such as $(...)) are evaluated by the remote shell when a terminal is opened. This can lead to arbitrary command execution on the remote host under the victim user's account. This vulnerability is fixed in 0.227.1.

Source: NVD

References

Related CVEs

Same vendor

Same CWE

  • CVE-2026-11527 Config::IniFiles versions before 3.001000 for Perl allow OS command injection and file overwrite via a 2-arg open() of the -file argument...
  • CVE-2026-11526 GD versions before 2.86 for Perl allow OS command injection and file overwrite via a 2-arg open() of filename arguments in _make_filehandle
  • CVE-2026-46716 Nezha Monitoring is a self-hostable, lightweight, servers and websites monitoring and O&M tool (9.9 CRITICAL)
  • CVE-2026-42853 ApostropheCMS is an open-source Node.js content management system (6.5 MEDIUM)
  • CVE-2026-48165 MariaDB server is a community developed fork of MySQL server (8.0 HIGH)