Zed IDE MCP Configuration Code Execution

Affected Vendor(s)

Affected Product(s)

Summary

The Zed IDE loads Model Context Protocol (MCP) configurations from the settings.json file located within a project’s .zed subdirectory. A malicious MCP configuration can contain arbitrary shell commands that run on the host system with the privileges of the user running the IDE. This can be triggered automatically without any user interaction besides opening the project in the IDE.

Timeline

Discovered on
November 14, 2025
Disclosed to Vendor on
November 16, 2025
Published on
December 17, 2025

Credit

Blog Post

References

Learn how Mindgard can help you navigate AI Security

Take the first step towards securing your AI. Book a demo now and we'll reach out to you.