Advisory #8
Titlevscode-rufo remote code execution via crafted workspace configuration
CVE IDCVE-2021-29658
Vendorjnbt
Affected productvscode-rufo
Affected versions- 0.0.3
Vulnerability typeCWE-284 (Improper Access Control)
Descriptionvscode-rufo has a vulnerability that allows a crafted workspace folder to execute arbitrary binaries, which leads remote code execution.
StatusFixed in 0.0.4
RecommendationUpdate to version 0.0.4 or later.