Phying News
Curated security research, vulnerabilities, advisories and tools for practitioners.

[CVE-2022-41042] Escaping well-configured VSCode extensions (for profit)

Summary

Part two of the series: bypassing a Webview's localResourceRoots via URL parsing differences in VSCode's Electron browser to read arbitrary files; fixed as CVE-2022-41042 with a $7,500 bounty.
Published
Collected

original ↗

Related coverage

back