PT-2021-18152 · Unknown · Unofficial Svelte Extension For Visual Studio Code

Ryotak

·

Published

2021-04-05

·

Updated

2021-04-08

·

CVE-2021-29261

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: Unofficial Svelte extension for Visual Studio Code versions prior to 104.8.0
Description: The issue allows attackers to execute arbitrary code via a crafted workspace configuration. This can be achieved by manipulating the workspace settings in a way that enables the execution of malicious code.
Recommendations: For versions prior to 104.8.0, update to version 104.8.0 or later to resolve the issue. As a temporary workaround, consider restricting access to workspace configuration files to minimize the risk of exploitation.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2021-29261

Affected Products

Unofficial Svelte Extension For Visual Studio Code