Ad

CVE-2026-27967

HIGH CVSS 3.1: 7.1 EPSS 0.01%
Updated Feb 26, 2026
Zed
Parameter Value
CVSS 7.1 (HIGH)
Affected Versions before 0.225.9
Type CWE-59 (Improper Link Resolution)
Vendor Zed
Public PoC No

Zed, a code editor, has a symlink escape vulnerability in versions prior to 0.225.9 in Agent file tools (`read_file`, `edit_file`). It allows reading and writing files **outside the project directory** when a project contains symbolic links pointing to external paths. This bypasses the intended workspace boundary and privacy protections (`file_scan_exclusions`, `private_files`), potentially leaking sensitive user data to the LLM.

Version 0.225.9 fixes the issue.

Attack Parameters

Attack Vector
Local
Requires local access
Attack Complexity
Low
Easy to exploit
Privileges Required
None
No privileges needed
User Interaction
Required
User action required

Impact Assessment

Confidentiality
High
Complete data leak
Integrity
High
Complete data modification
Availability
None
No disruption

CVSS Vector v3.1