We use cookies to improve your experience on our site.
AVID-2026-R0425
Description
Zed IDE MCP Configuration Code Execution
Details
The Zed IDE loads Model Context Protocol (MCP) configurations from the settings.json file located within a project’s .zed subdirectory. A malicious MCP configuration can contain arbitrary shell commands that run on the host system with the privileges of the user running the IDE. This can be triggered automatically without any user interaction besides opening the project in the IDE.
References
Affected or Relevant Artifacts
- Developer: Zed Industries
- Deployer:
- Artifact Details:
| Type | Name |
|---|---|
| System | Zed IDE |
Impact
- (none)
Other information
- Report Type: Advisory
- Credits: Aaron Portnoy, Mindgard
- Date Reported: 2025-11-16
- Version: 0.3.1
- AVID Entry