CVE-2026-44463: Zed

High severity, CVSS 7.8. EPSS: 0.2% chance of exploitation in the next 30 days.

Zed is a code editor. Prior to 0.229.0, Zed's terminal tool permission system can be bypassed by prepending environment variable assignments to allowlisted commands, hijacking program behavior (e.g., PAGER) to execute arbitrary code. This vulnerability is fixed in 0.229.0.

Affected products

  • Zed Zed: before 0.229.0 (fixed in 0.229.0)

Published 2026-05-28. Last modified 2026-06-17.