[CVE-2022-41042] Escaping well-configured VSCode extensions (for profit)
blog.trailofbits.com | blog | CVE-2022-41042 | #arbitrary-file-read | #vulnerability-research | #path-traversal | #vulnerability-disclosure | #webview | #trail-of-bits | #electron | #vscode | #cve-2022-41042 | #url-parsing
Summary
Part two of the series: bypassing a Webview's localResourceRoots via URL parsing differences in VSCode's Electron browser to read arbitrary files; fixed as CVE-2022-41042 with a $7,500 bounty.
- Published
- Collected
Skip to content