VYPR
High severity7.1NVD Advisory· Published Feb 26, 2026· Updated Jun 17, 2026

CVE-2026-27967

CVE-2026-27967

Description

Zed, a code editor, has a symlink escape vulnerability in versions prior to 0.225.9 in Agent file tools (read_file, edit_file). It allows reading and writing files outside the project directory when a project contains symbolic links pointing to external paths. This bypasses the intended workspace boundary and privacy protections (file_scan_exclusions, private_files), potentially leaking sensitive user data to the LLM. Version 0.225.9 fixes the issue.

Affected products

3
  • cpe:2.3:a:zed:zed:*:*:*:*:*:*:*:*
    Range: <0.225.9
  • Zed Industries/Zedllm-fuzzy2 versions
    <0.225.9+ 1 more
    • (no CPE)range: <0.225.9
    • (no CPE)range: < 0.225.9

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.