Security: zed-industries/zed
Security
No security policy detected
This project has not set up a SECURITY.md file yet.
Report a vulnerability-
Symlink Escape in Agent File ToolsGHSA-786m-x2vc-5235 published
Feb 25, 2026 by swannysecHigh -
Zed Extension Sandbox Escape via Tar Symlink FollowingGHSA-59p4-3mhm-qm3r published
Feb 25, 2026 by swannysecHigh -
Zip Slip Path Traversal in Extension Archive ExtractionGHSA-v385-xh3h-rrfr published
Feb 25, 2026 by swannysecHigh -
Parameter Values are not shown for MCP Tool Calls. Users cannot detect tool poisoning.GHSA-f2g4-87h6-4pxq published
Feb 10, 2026 by swannysecModerate -
Zed IDE LSP Binary Configuration Arbitrary Code ExecutionGHSA-29cp-2hmh-hcxj published
Dec 17, 2025 by swannysecHigh -
Zed IDE MCP Context Server Configuration Arbitrary Code ExecutionGHSA-cv6g-cmxc-vw8j published
Dec 17, 2025 by swannysecHigh -
AI Agent Remote Code ExecutionGHSA-x34m-39xw-g2wr published
Aug 11, 2025 by JosephTLyonsCritical
Learn more about advisories related to zed-industries/zed in the GitHub Advisory Database