VYPR
Unrated severityNVD Advisory· Published Feb 25, 2026· Updated Feb 28, 2026

Symlink Escape in Agent File Tools

CVE-2026-27967

Description

Zed, a code editor, has a symlink escape vulnerability in versions prior to 0.225.9 in Agent file tools (read_file, edit_file). It allows reading and writing files outside the project directory when a project contains symbolic links pointing to external paths. This bypasses the intended workspace boundary and privacy protections (file_scan_exclusions, private_files), potentially leaking sensitive user data to the LLM. Version 0.225.9 fixes the issue.

Affected products

2
  • Zed Industries/Zedllm-fuzzy2 versions
    <0.225.9+ 1 more
    • (no CPE)range: <0.225.9
    • (no CPE)range: < 0.225.9

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.