Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-25805

Опубликовано: 10 фев. 2026
Источник: nvd
CVSS3: 6.4
CVSS3: 8
EPSS Низкий

Описание

Zed is a multiplayer code editor. Prior to 0.219.4, Zed does not show with which parameters a tool is being invoked, when asking for allowance. Further it does not show after the tool was being invoked, which parameters were used. Thus, maybe unwanted or even malicious values could be used without the user having a chance to notice it. Patched in Zed Editor 0.219.4 which includes expandable tool call details.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:zed:zed:*:*:*:*:*:*:*:*
Версия до 0.219.4 (исключая)

EPSS

Процентиль: 18%
0.00058
Низкий

6.4 Medium

CVSS3

8 High

CVSS3

Дефекты

CWE-356

Связанные уязвимости

CVSS3: 6.4
debian
около 2 месяцев назад

Zed is a multiplayer code editor. Prior to 0.219.4, Zed does not show ...

EPSS

Процентиль: 18%
0.00058
Низкий

6.4 Medium

CVSS3

8 High

CVSS3

Дефекты

CWE-356