The unofficial vscode-rufo extension before 0.0.4 for Visual Studio Code allows attackers to execute arbitrary binaries if the user opens a crafted workspace folder.
Affected Software
Name |
Vendor |
Start Version |
End Version |
Vscode-rufo |
Vscode-rufo_project |
* |
0.0.4 (excluding) |
References