VSCodeVim before 1.19.0 allows attackers to execute arbitrary code via a crafted workspace configuration.
Link | Tags |
---|---|
https://marketplace.visualstudio.com/items?itemName=vscodevim.vim | product third party advisory |
https://vuln.ryotak.me/advisories/9 | third party advisory |
https://github.com/VSCodeVim/Vim/commit/939df0e7fd55a9840dbd4fb3c907315e2a5ef446 | third party advisory patch |