Advisory #9
TitleVSCodeVim remote code execution via crafted workspace configuration
CVE IDCVE-2021-28832
VendorVSCodeVim
Affected productVSCodeVim
Affected versions- 1.18.9
Vulnerability typeCWE-284 (Improper Access Control)
DescriptionVSCodeVim has a vulnerability that allows a crafted workspace folder to execute arbitrary binaries, which leads remote code execution.
StatusFixed in 1.19.0
RecommendationUpdate to version 1.19.0 or above