Advisory #1
Titlevscode-sass-lint (aka Sass Lint) remote code execution via crafted workspace configuration
CVE IDCVE-2021-28956
VendorGlen
Affected productvscode-sass-lint
Affected versions- 1.0.7
Vulnerability typeCWE-284 (Improper Access Control)
Descriptionvscode-sass-lint has a vulnerability that allows a crafted workspace folder to execute arbitrary binaries, which leads remote code execution.
StatusNo fix available
RecommendationUse vscode-stylelint as recommended by the vendor.