Advisory #13
| Title | SwiftFormat for VS Code remote code execution via crafted workspace configuration | 
| CVE ID | CVE-2021-28791 | 
| Vendor | Valentin Knabel | 
| Affected product | SwiftFormat for VS Code | 
| Affected versions | - 1.3.6 | 
| Vulnerability type | CWE-284 (Improper Access Control) | 
| Description | SwiftFormat for VS Code has a vulnerability that allows a crafted workspace folder to execute arbitrary binaries, which leads remote code execution. | 
| Status | Fixed in 1.3.7 | 
| Recommendation | Update to 1.3.7 or above |