Skip to content

Python extension for Visual Studio Code Remote Code Execution Vulnerability #24428

Closed
@karthiknadig

Description

@karthiknadig

There is a security vulnerability in the untrusted workspaces flow with specially crafted workspaces.

Patches

The fix is available starting with 2024.20.0 fix is: a16ed6b

Workarounds

Check for python executables checked-into SCM before opening untrusted workspaces.

References

Metadata

Metadata

Assignees

Labels

bugIssue identified by VS Code Team member as probable bugneeds PRReady to be worked on

Type

No type

Projects

No projects

Relationships

None yet

Development

No branches or pull requests

Issue actions