CVE 7.8 HIGH

Zed IDE MCP Context Server Configuration Arbitrary Code Execution_CVE-2025-68433

7.8 / 10
HIGH
CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H

Description

Zed, a code editor, has an aribtrary code execution vulnerability in versions prior to 0.218.2-pre. The Zed IDE loads Model Context Protocol (MCP) configurations from the `settings.json` file located within a project’s `.zed` subdirectory. A malicious MCP configuration can contain arbitrary shell commands that run on the host system with the privileges of the user running the IDE. This can be triggered automatically without any user interaction besides opening the project in the IDE. Version 0.218.2-pre fixes the issue by implementing worktree trust mechanism. As a workaround, users should carefully review the contents of project settings files (`./zed/settings.json`) before opening new projects in Zed.

Basic Information

ID CVE-2025-68433
Source GitHub_M
Published Dec 17, 2025 at 22:47

Affected Product

Vendor zed-industries
Product zed
Version < 0.218.2-pre
Affected Versions zed-industries zed < 0.218.2-pre

CWE Classification

References

πŸ’­ Join the Security Discussion

πŸ”’ Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.