CVE-2025-55012 - CVE House
Back to Database
Status published High CVE-2025-55012

Zed AI Agent Remote Code Execution

Vulnerability Description

Zed is a multiplayer code editor. Prior to version 0.197.3, in the Zed Agent Panel allowed for an AI agent to achieve Remote Code Execution (RCE) by bypassing user permission checks. An AI Agent could have exploited a permissions bypass vulnerability to create or modify a project-specific configuration file, leading to the execution of arbitrary commands on a victim's machine without the explicit approval that would otherwise be required. This vulnerability has been patched in version 0.197.3. A workaround for this issue involves either avoid sending prompts to the Agent Panel, or to limit the AI Agent's file system access.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-55012

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

zed-industries

View all reports →

Affected Software

zed
Vulnerable Versions:
< 0.197.3

Timeline

Official Publish: August 11th, 2025
Last Modified: August 12th, 2025
Added to House: July 22nd, 2026

CVSS Vectors

Weaknesses (CWE)