vendor:
Visual Studio Code
by:
Doyensec
7.5
CVSS
HIGH
Code Execution
94
CWE
Product Name: Visual Studio Code
Affected Version From:
Affected Version To:
Patch Exists: NO
Related CWE:
CPE: a:microsoft:visual_studio_code
Platforms Tested: macOS
2020
VSCode Python Extension Code Execution
VScode may use code from a virtualenv found in the project folders without asking the user, leading to arbitrary code execution by cloning and opening a malicious Python repository.
Mitigation:
Update to the latest version of the Visual Studio Code Python extension.