Phying News
Curated security research, vulnerabilities, advisories and tools for practitioners.

[CVE-2022-41042] Escaping misconfigured VSCode extensions

Summary

Part one of the series: three vulnerabilities in Microsoft's SARIF Viewer and Live Preview VSCode extensions enabling local file theft, plus the $7,500-bounty CVE-2022-41042 mitigation bypass.
Published
Collected

original ↗

Related coverage

back