Closed
Description
There is a security vulnerability in the untrusted workspaces flow with specially crafted workspaces.
Patches
The fix is available starting with 2024.20.0 fix is: a16ed6b
Workarounds
Check for python executables checked-into SCM before opening untrusted workspaces.
References
- The patch for this can be found at a16ed6b
- MSRC details for this can be found at https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-49050
- Security advisory: GHSA-cmrx-fhfp-pq36