2025 Zed — CVE-2025-68433 MCP/LSP arbitrary code execution
Data compromised
Potential: user system access; code execution
Technical writeup
Mindgard found two high-severity flaws: MCP configs in .zed/settings.json could execute arbitrary shell commands; LSP configs could run commands when opening files. Malicious projects could auto-execute. Worktree trust (0.218.2) added. CVSS 7.8.
Root cause
Arbitrary code execution; untrusted config loading