« Volver al listado

CVE-2026-27976

Estado: AnalizadaAlta (8.8)—

Zed, a code editor, has an extension installer allows tar/gzip downloads. Prior to version 0.224.4, the tar extractor (`async_tar::Archive::unpack`) creates symlinks from the archive without validation, and the path guard (`writeable_path_from_extension`) only performs lexical prefix checks without resolving symlinks. An attacker can ship a tar that first creates a symlink inside the extension workdir pointing outside (e.g., `escape -> /`), then writes files through the symlink, causing writes to arbitrary host paths. This escapes the extension sandbox and enables code execution. Version 0.224.4 patches the issue.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

🎯 Técnicas ATT&CK

Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.

UI:R + descarga/instalación de extensión = ejecución en cliente. Symlink traversal permite escribir ficheros arbitrarios → ejecución de código. T1574.008 (DLL/librería) por manipulación de rutas.

Inferido por nuestro agente de análisis a partir de la descripción oficial, el vector CVSS y la CWE, y comprobado por un supervisor. Puede contener errores.

🛡️ Mitigaciones ATT&CK que cubren estas técnicas

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-27976",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2026-27976",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "poc"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "total"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2026-02-26T00:00:00+00:00"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "security-advisories@github.com",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 8.8,
          "attackVector": "NETWORK",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "REQUIRED",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 2.8
      }
    ]
  },
  "affected": [
    {
      "source": "security-advisories@github.com",
      "affectedData": [
        {
          "vendor": "zed-industries",
          "product": "zed",
          "versions": [
            {
              "status": "affected",
              "version": "< 0.224.4"
            }
          ]
        }
      ]
    }
  ],
  "published": "2026-02-26T00:16:27.293",
  "references": [
    {
      "url": "https://github.com/zed-industries/zed/security/advisories/GHSA-59p4-3mhm-qm3r",
      "tags": [
        "Exploit",
        "Mitigation",
        "Vendor Advisory"
      ],
      "source": "security-advisories@github.com"
    }
  ],
  "vulnStatus": "Analyzed",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "security-advisories@github.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-61"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Zed, a code editor, has an extension installer allows tar/gzip downloads. Prior to version 0.224.4, the tar extractor (`async_tar::Archive::unpack`) creates symlinks from the archive without validation, and the path guard (`writeable_path_from_extension`) only performs lexical prefix checks without resolving symlinks. An attacker can ship a tar that first creates a symlink inside the extension workdir pointing outside (e.g., `escape -> /`), then writes files through the symlink, causing writes to arbitrary host paths. This escapes the extension sandbox and enables code execution. Version 0.224.4 patches the issue."
    },
    {
      "lang": "es",
      "value": "Zed, un editor de código, tiene un instalador de extensiones que permite descargas tar/gzip. Antes de la versión 0.224.4, el extractor de tar ('async_tar::Archive::unpack') crea enlaces simbólicos (symlinks) desde el archivo sin validación, y el protector de rutas ('writeable_path_from_extension') solo realiza comprobaciones de prefijo léxico sin resolver enlaces simbólicos (symlinks). Un atacante puede enviar un tar que primero crea un enlace simbólico (symlink) dentro del directorio de trabajo de la extensión apuntando hacia afuera (por ejemplo, 'escape -&gt; /'), luego escribe archivos a través del enlace simbólico (symlink), provocando escrituras en rutas de host arbitrarias. Esto escapa de la sandbox de la extensión y permite la ejecución de código. La versión 0.224.4 soluciona el problema."
    }
  ],
  "lastModified": "2026-06-17T10:28:00.213",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:zed:zed:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "63C50DD7-F03F-4305-94DE-F5BFF201BA6A",
              "versionEndExcluding": "0.224.4"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "security-advisories@github.com"
}