The unofficial vscode-rpm-spec extension before 0.3.2 for Visual Studio Code allows remote code execution via a crafted workspace configuration.
Link | Tags |
---|---|
https://vuln.ryotak.me/advisories/36 | third party advisory |
https://github.com/LaurentTreguier/vscode-rpm-spec/commit/e19fb8e29cb48cadfd3238371e060d4ffd3384f9 | third party advisory patch |