The unofficial Svelte extension before 104.8.0 for Visual Studio Code allows attackers to execute arbitrary code via a crafted workspace configuration.
Link | Tags |
---|---|
https://marketplace.visualstudio.com/items?itemName=svelte.svelte-vscode | third party advisory product |
https://github.com/sveltejs/language-tools/releases | third party advisory |
https://vuln.ryotak.me/advisories/3 | third party advisory |
https://github.com/sveltejs/language-tools/releases/tag/extensions-104.8.0 | third party advisory release notes |
https://github.com/sveltejs/language-tools/commit/5d7bf1fd98bfe2cd2080863a3c95ce099b898075 | third party advisory patch |