Arbitrary Code Execution Vulnerability in Zed IDE by Zed Industries
CVE-2025-68433
7.8HIGH
What is CVE-2025-68433?
Zed IDE, a popular code editor, is susceptible to an arbitrary code execution flaw due to improper handling of Model Context Protocol (MCP) configurations. This vulnerability allows malicious MCP configurations to execute shell commands on the user's host system with the same privileges as the running IDE. The exploitation occurs automatically when a project containing a compromised settings.json file is opened, without any direct user interaction. Users are urged to upgrade to version 0.218.2-pre which mitigates the risk through a worktree trust mechanism. As a precautionary measure, reviewing ./zed/settings.json before opening new projects can help prevent potential attacks.
Affected Version(s)
zed < 0.218.2-pre
