Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

msrc логотип

CVE-2021-26700

Опубликовано: 09 фев. 2021
Источник: msrc
CVSS3: 7.8
EPSS Средний

Описание

Visual Studio Code npm-script Extension Remote Code Execution Vulnerability

FAQ

How could an attacker exploit this vulnerability?

To exploit this vulnerability, an attacker would need to convince a targeted user to clone a malicious repository. Attacker-specified code would execute once the targeted user viewed contents of the repository in Visual Studio Code.

Обновления

ПродуктСтатьяОбновление
Visual Studio Code - npm-script Extension

Показывать по

Возможность эксплуатации

Publicly Disclosed

No

Exploited

No

Latest Software Release

Exploitation Less Likely

Older Software Release

Exploitation Less Likely

DOS

N/A

EPSS

Процентиль: 94%
0.12921
Средний

7.8 High

CVSS3

Связанные уязвимости

CVSS3: 7.8
nvd
почти 5 лет назад

Visual Studio Code npm-script Extension Remote Code Execution Vulnerability

github
больше 3 лет назад

Remote code execution in vscode-npm-script

EPSS

Процентиль: 94%
0.12921
Средний

7.8 High

CVSS3