Описание
The unofficial Svelte extension before 104.8.0 for Visual Studio Code allows attackers to execute arbitrary code via a crafted workspace configuration.
The unofficial Svelte extension before 104.8.0 for Visual Studio Code allows attackers to execute arbitrary code via a crafted workspace configuration.
Ссылки
- https://nvd.nist.gov/vuln/detail/CVE-2021-29261
- https://github.com/sveltejs/language-tools/commit/5d7bf1fd98bfe2cd2080863a3c95ce099b898075
- https://github.com/sveltejs/language-tools/releases
- https://github.com/sveltejs/language-tools/releases/tag/extensions-104.8.0
- https://marketplace.visualstudio.com/items?itemName=svelte.svelte-vscode
- https://vuln.ryotak.me/advisories/3
EPSS
Процентиль: 71%
0.00681
Низкий
CVE ID
Связанные уязвимости
CVSS3: 7.8
nvd
почти 5 лет назад
The unofficial Svelte extension before 104.8.0 for Visual Studio Code allows attackers to execute arbitrary code via a crafted workspace configuration.
EPSS
Процентиль: 71%
0.00681
Низкий