Advisory #37
TitlereStructuredText Language Support for Visual Studio Code remote code execution via crafted workspace configuration
CVE IDCVE-2021-28793
VendorreStructuredText Language Support for Visual Studio Code
Affected productreStructuredText Language Support for Visual Studio Code
Affected versions- 146.0.0
Vulnerability typeCWE-284 (Improper Access Control)
DescriptionreStructuredText Language Support for Visual Studio Code has a vulnerability that allows a crafted workspace folder to execute arbitrary binaries, which leads remote code execution.
StatusFixed in 147.0.0
RecommendationUpdate to 147.0.0 or above