Junglewise Threat Intelligence

CVE-2026-44466: Zed Industries Zed command injection in terminal tool permissions

CVE-2026-44466 · Severity: high · CVSS 8.6 · Published 2026-05-28

Technologies: Zed Industries Zed. Vendors: Zed Industries.

Executive brief

Zed is a high-performance code editor. A security flaw in its terminal tool permission system allows an attacker to bypass security restrictions and run unauthorized commands on a user's computer. This could lead to full system compromise, data theft, or malicious software installation if a user is tricked into running a seemingly safe command through the editor's AI features.

Technical details

An OS command injection vulnerability exists in Zed's terminal tool permission system due to improper neutralization of shell metacharacters. The system uses regex patterns (e.g., '^echo\b') to validate allowlisted commands but fails to account for bash arithmetic expansion syntax '$((...))'. An attacker can embed arbitrary commands within this syntax, such as 'echo $(($(malicious_cmd)))', which bypasses the regex check and executes the nested command in the shell. This can be triggered via prompt injection if an attacker influences the AI agent's tool calls. The issue is fixed in version 0.229.0.

Affected products

  • Zed Industries Zed < 0.229.0

Timeline

  • 2026-05-08: advisory: Original GitHub security advisory published
  • 2026-05-28: disclosed: CVE published to NVD
  • 2026-05-28: patched: Fix released in version 0.229.0

References

Related threats