Phying News
Curated security research, vulnerabilities, advisories and tools for practitioners.

Supply Chain Security Analysis of a 9.5M-Install VS Code Extension

Summary

Your code editor extensions auto-update and run with your privileges on the machine that holds your source code, your SSH keys, and your publishing credentials, but they rarely show up in a software bill of materials. Using Neo we audited one of the most popular ones, Markdown Preview Enhanced has roughly 9.5 million installs. The neo found five CVEs across two attack surfaces. A WaveDrom rendering bug turned an ordinary Markdown file into JavaScript execution inside the preview, then into arb
Published
Collected

original ↗

Related coverage

back