Advisory #12
| Title | SwiftLint for VS Code remote code execution via crafted workspace configuration |
| CVE ID | CVE-2021-28790 |
| Vendor | Valentin Knabel |
| Affected product | SwiftLint for VS Code |
| Affected versions | - 1.4.4 |
| Vulnerability type | CWE-284 (Improper Access Control) |
| Description | SwiftLint for VS Code has a vulnerability that allows a crafted workspace folder to execute arbitrary binaries, which leads remote code execution. |
| Status | Fixed in 1.4.5 |
| Recommendation | Update to 1.4.5 or above |