Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2026-44462

Опубликовано: 28 мая 2026
Источник: debian
EPSS Низкий

Описание

Zed is a code editor. Prior to 0.229.0, Zed's terminal tool permission system can be bypassed via bash variable expansion chaining (${var@P}), allowing arbitrary command execution under an allowlisted command prefix. This vulnerability is fixed in 0.229.0.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
zed-editoritppackage

EPSS

Процентиль: 36%
0.00438
Низкий

Связанные уязвимости

CVSS3: 6.4
ubuntu
3 месяца назад

Zed is a code editor. Prior to 0.229.0, Zed's terminal tool permission system can be bypassed via bash variable expansion chaining (${var@P}), allowing arbitrary command execution under an allowlisted command prefix. This vulnerability is fixed in 0.229.0.

CVSS3: 6.4
nvd
3 месяца назад

Zed is a code editor. Prior to 0.229.0, Zed's terminal tool permission system can be bypassed via bash variable expansion chaining (${var@P}), allowing arbitrary command execution under an allowlisted command prefix. This vulnerability is fixed in 0.229.0.

EPSS

Процентиль: 36%
0.00438
Низкий