Home » Database

AVID-2026-R0425

Description

Zed IDE MCP Configuration Code Execution

Details

The Zed IDE loads Model Context Protocol (MCP) configurations from the settings.json file located within a project’s .zed subdirectory. A malicious MCP configuration can contain arbitrary shell commands that run on the host system with the privileges of the user running the IDE. This can be triggered automatically without any user interaction besides opening the project in the IDE.

References

Affected or Relevant Artifacts

  • Developer: Zed Industries
  • Deployer:
  • Artifact Details:
TypeName
SystemZed IDE

Impact

  • (none)

Other information

  • Report Type: Advisory
  • Credits: Aaron Portnoy, Mindgard
  • Date Reported: 2025-11-16
  • Version: 0.3.1
  • AVID Entry