Skip to content
MicrosoftGHSA-4v3r-wv86-6mjj

Remote Code Execution Vulnerability

HighCVE-2023-24893 · Published Apr 11, 2023 · updated Apr 12, 2023

### Impact A vulnerability exists in VS Code 1.77.0 and earlier versions where escape sequences implemented by VS Code to support shell integration allow for a previously run command line to be replaced. As such, a user could be running a changed command unexpectedly when they use `re-run command`. ### Patches The fix is available starting with VS Code 1.77.1. The fix (6740c2ec22889c9e3c944917ff6377f43326a096) mitigates this by showing the user a notification with the command that is to be run and requires their approval to do so. ### References - The patch for this can be found at 6740c2ec22889c9e3c944917ff6377f43326a096 - An issue for this can be found at https://github.com/microsoft/vscode/issues/179701 - MSRC details for this can be found at https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-24893

GitHub advisory

Affected versions

PackageAffectedFixed in
vscode
Product
< 1.77.11.77.1
Details and references

More Microsoft advisories

All Microsoft
Advisory
Remote Code Execution Vulnerability
HighSep 12, 2023
Remote Code Execution Vulnerability
HighSep 12, 2023
Information Disclosure Vulnerability
HighJun 13, 2023
Information Disclosure Vulnerability
HighMay 9, 2023
Remote Code Execution Vulnerability
MediumJan 10, 2023
Information Disclosure Vulnerability
MediumOct 11, 2022

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.