Advisory #37
Title | reStructuredText Language Support for Visual Studio Code remote code execution via crafted workspace configuration |
CVE ID | CVE-2021-28793 |
Vendor | reStructuredText Language Support for Visual Studio Code |
Affected product | reStructuredText Language Support for Visual Studio Code |
Affected versions | - 146.0.0 |
Vulnerability type | CWE-284 (Improper Access Control) |
Description | reStructuredText Language Support for Visual Studio Code has a vulnerability that allows a crafted workspace folder to execute arbitrary binaries, which leads remote code execution. |
Status | Fixed in 147.0.0 |
Recommendation | Update to 147.0.0 or above |