Advisory #10
TitleShellCheck for Visual Studio Code remote code execution via crafted workspace configuration
CVE IDCVE-2021-28794
VendorTimon Wong
Affected productShellCheck for Visual Studio Code
Affected versions- v0.13.3
Vulnerability typeCWE-284 (Improper Access Control)
DescriptionShellCheck for Visual Studio Code has a vulnerability that allows a crafted workspace folder to execute arbitrary binaries, which leads remote code execution.
StatusFixed in v0.13.4
RecommendationUpdate to v0.13.4 or above