Advisory #14
TitleSwift Development Environment for VS Code remote code execution via crafted workspace configuration
CVE IDCVE-2021-28792
VendorValentin Knabel
Affected productSwift Development Environment for VS Code
Affected versions- 2.12.0
Vulnerability typeCWE-284 (Improper Access Control)
DescriptionSwift Development Environment for VS Code has a vulnerability that allows a crafted workspace folder to execute arbitrary binaries, which leads remote code execution.
StatusFixed in 2.12.1
RecommendationUpdate to 2.12.1 or above