Three of the four vulnerabilities remained unpatched months after OX Security reported them to the maintainers.
Attackers can abuse VS Code configuration files for RCE when a GitHub Codespaces user opens a repository or pull request.
Critical vulnerabilities in four widely used VS Code extensions could enable file theft and remote code execution across 125M installs.
VS Code's official Snap package on Linux has a bug first reported in 2024 that still hasn't been fixed and is gobbling up storage space.