PT-2023-29927 · Microsoft · Vscode
Andreeleuterio
·
Publicado
2023-10-31
·
Atualizado
2023-11-08
·
CVE-2023-46248
CVSS v3.1
9.0
Crítica
| Vetor | AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Cody AI VSCode extension versions 0.10.0 through 0.14.0
Description
The issue concerns Remote Code Execution under certain conditions. An attacker in control of a malicious repository could modify the Cody configuration file
.vscode/cody.json and overwrite Cody commands. If a user with the extension installed opens this malicious repository and runs a Cody command such as /explain or /doc, this could allow arbitrary code execution on the user's machine. The issue is exploitable regardless of the user blocking code execution on a repository through VS Code Workspace Trust. It was found during a regular 3rd party penetration test. The maintainers do not have evidence of open source repositories having malicious .vscode/cody.json files to exploit this issue.Recommendations
For Cody AI VSCode extension versions 0.10.0 through 0.14.0, upgrade to version 0.14.1 to fix the issue.
In case users can't promptly upgrade, they should not open any untrusted repositories with the Cody extension loaded.
Exploit
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Vscode