Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Wed, 03 Jun 2026 02:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Zed
Zed zed |
|
| CPEs | cpe:2.3:a:zed:zed:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Zed
Zed zed |
Fri, 29 May 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
ssvc
|
Thu, 28 May 2026 19:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Zed-industries
Zed-industries zed |
|
| Vendors & Products |
Zed-industries
Zed-industries zed |
Thu, 28 May 2026 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 28 May 2026 17:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Zed is a code editor. Prior to 0.229.0, Zed's terminal tool permission system can be bypassed via bash arithmetic expansion $((...)), allowing execution of arbitrary commands nested inside an allowlisted command like echo. This vulnerability is fixed in 0.229.0. | |
| Title | Zed: Allowlist Bypass via Bash Arithmetic Expansion in Terminal Tool Permissions | |
| Weaknesses | CWE-78 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-05-29T15:15:18.570Z
Reserved: 2026-05-06T15:49:25.193Z
Link: CVE-2026-44466
Updated: 2026-05-28T19:10:16.026Z
Status : Analyzed
Published: 2026-05-28T17:16:30.317
Modified: 2026-06-02T20:14:36.660
Link: CVE-2026-44466
No data.
OpenCVE Enrichment
Updated: 2026-05-28T19:30:16Z