Unrated severityNVD Advisory· Published Feb 25, 2026· Updated Feb 26, 2026
Zed has Zip Slip Path Traversal in Extension Archive Extraction
CVE-2026-27800
Description
Zed, a code editor, has a Zip Slip (Path Traversal) vulnerability exists in its extension archive extraction functionality prior to version 0.224.4. The extract_zip() function in crates/util/src/archive.rs fails to validate ZIP entry filenames for path traversal sequences (e.g., ../). This allows a malicious extension to write files outside its designated sandbox directory by downloading and extracting a crafted ZIP archive. Version 0.224.4 fixes the issue.
Affected products
1- Range: < 0.224.4
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1- github.com/zed-industries/zed/security/advisories/GHSA-v385-xh3h-rrfrmitrex_refsource_CONFIRM
News mentions
0No linked articles in our index yet.