CVE-2025-55012 Details
Description
Zed is a multiplayer code editor. Prior to version 0.197.3, in the Zed Agent Panel allowed for an AI agent to achieve Remote Code Execution (RCE) by bypassing user permission checks. An AI Agent could have exploited a permissions bypass vulnerability to create or modify a project-specific configuration file, leading to the execution of arbitrary commands on a victim's machine without the explicit approval that would otherwise be required. This vulnerability has been patched in version 0.197.3. A workaround for this issue involves either avoid sending prompts to the Agent Panel, or to limit the AI Agent's file system access.
A remote code execution vulnerability has been identified in Zed, a multiplayer code editor, prior to version 0.197.3. The issue arises in the Zed Agent Panel, where an AI agent could bypass user permission checks to execute arbitrary commands on a victim's machine. This was achieved by exploiting the permissions bypass to create or modify a project-specific configuration file, without the necessary explicit approval. The vulnerability has been patched in version 0.197.3.
Users are advised to upgrade to version 0.197.3 or later. For those unable to upgrade immediately, it is recommended to avoid sending prompts to the Agent Panel or to limit the AI Agent's file system access by deselecting tools that can write to the filesystem or by switching to a more restrictive tool profile.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Aug 11, 2025CISA-ADP
Assessed Aug 12, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/zed-industries/zed/security/advisories/GHSA-x34m-39xw-g2wr | [email protected] | AdvisoryRemedyVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-284 | Improper Access Control | [email protected] |
| CWE-288 | Authentication Bypass Using an Alternate Path or Channel | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Zed | All versions |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Aug 11, 2025 | New CVE Received | [email protected] |
Volerion