Unrated severityNVD Advisory· Published Feb 25, 2026· Updated Feb 28, 2026
Symlink Escape in Agent File Tools
CVE-2026-27967
Description
Zed, a code editor, has a symlink escape vulnerability in versions prior to 0.225.9 in Agent file tools (read_file, edit_file). It allows reading and writing files outside the project directory when a project contains symbolic links pointing to external paths. This bypasses the intended workspace boundary and privacy protections (file_scan_exclusions, private_files), potentially leaking sensitive user data to the LLM. Version 0.225.9 fixes the issue.
Affected products
1- Range: < 0.225.9
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1- github.com/zed-industries/zed/security/advisories/GHSA-786m-x2vc-5235mitrex_refsource_CONFIRM
News mentions
0No linked articles in our index yet.