Summary
Researchers discovered critical vulnerabilities in VS Code extensions that allow remote code execution and local file theft. The flaws affect Code Runner, Live Server, and Markdown Preview Enhanced, exposing sensitive credentials and proprietary source code.
Take Action:
If you use VS Code (or Cursor/Windsurf) with the Live Server, Code Runner, or Markdown Preview Enhanced extensions, be aware they have unpatched critical flaws. Remove them unless you they are absolutely necessary and irreplaceable. Update Microsoft Live Preview to version 0.4.16 or later right away. If you continue using them, never paste settings or config snippets from the internet into your editor, and don't open untrusted Markdown or project files while these extensions are active.
Read the full article on BeyondMachines
This article was originally published on BeyondMachines
Top comments (0)