PT-2021-18152 · Unknown · Unofficial Svelte Extension For Visual Studio Code
Ryotak
·
Published
2021-04-05
·
Updated
2021-04-08
·
CVE-2021-29261
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions:
Unofficial Svelte extension for Visual Studio Code versions prior to 104.8.0
Description:
The issue allows attackers to execute arbitrary code via a crafted workspace configuration. This can be achieved by manipulating the workspace settings in a way that enables the execution of malicious code.
Recommendations:
For versions prior to 104.8.0, update to version 104.8.0 or later to resolve the issue. As a temporary workaround, consider restricting access to workspace configuration files to minimize the risk of exploitation.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Unofficial Svelte Extension For Visual Studio Code