High severity7.1NVD Advisory· Published Feb 26, 2026· Updated Jun 17, 2026
CVE-2026-27967
CVE-2026-27967
Description
Zed, a code editor, has a symlink escape vulnerability in versions prior to 0.225.9 in Agent file tools (read_file, edit_file). It allows reading and writing files outside the project directory when a project contains symbolic links pointing to external paths. This bypasses the intended workspace boundary and privacy protections (file_scan_exclusions, private_files), potentially leaking sensitive user data to the LLM. Version 0.225.9 fixes the issue.
Affected products
3<0.225.9+ 1 more
- (no CPE)range: <0.225.9
- (no CPE)range: < 0.225.9
Patches
Vulnerability mechanics
References
1- github.com/zed-industries/zed/security/advisories/GHSA-786m-x2vc-5235nvdExploitMitigationVendor Advisory
News mentions
0No linked articles in our index yet.