Vulnerabilità · 117 giorni fa
Una sessione di VS Code basata su browser può consegnare a un attaccante molto più della pagina o del repo che l'utente ha aperto. Il punto debole è il collegamento di fiducia tra github.com e github.dev: una webview costruita ad arte può attivare i flussi di installazione delle extension e rubare il token OAuth di GitHub che github.dev riceve, che poi funziona su ogni repo a cui l'utente può accedere.
5 fonti che coprono questa storia
The Record from Recorded Future
Researcher publishes GitHub token-stealing exploit, blames Microsoft’s disclosure process
The security researcher, Ammar Askar, released the new proof-of-concept exploit on his personal blog — alongside the public tracker for issues in VS Code — giving a GitHub security contact roughly one hour's notice beforehand.
VS Code Vulnerability Allows One-Click GitHub Token Theft
A researcher has disclosed the full details of the vulnerability and released a PoC without notifying Microsoft in advance.
Microsoft Fixes One-Click GitHub Dev Attack That Let Attackers Steal OAuth Tokens
VS Code flaw exposes GitHub OAuth tokens via one-click attack on GitHub.dev, enabling private repo access and token theft.
Hole in GitHub’s browser-based VSCode editor could lead to stolen token
Its disclosure raises questions about what security researchers should expect from vendors, and how far in advance of its publication they should notify vendors about a bug.
VS Code zero-day lets hackers steal GitHub tokens in one click
A security researcher has released exploit code for a Visual Studio Code (VS Code) zero-day vulnerability that allows attackers to steal GitHub authentication tokens by tricking users into clicking a link.
Riepilogo fornitore: Microsoft
Part of the PlainSec briefing for 2026-06-03