Skip to content
StripeGHSA-j6x4-4622-8vv3

Vulnerability in Stripe for Visual Studio Code < 1.7.3

High7.5CVE-2021-21420 · Published Mar 31, 2021 · updated Apr 1, 2021

### Impact A vulnerability in Stripe for Visual Studio Code extension exists when it loads an untrusted source-code repository containing malicious settings. An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the current user. The update addresses the vulnerability by modifying the way the extension validates its settings. There has been no evidence of exploitation of this vulnerability. ### Recommendation Upgrade to Stripe for Visual Studio Code 1.7.3 ### Acknowledgments Thanks to [David Dworken](https://daviddworken.com) for reporting the issue. ### For more information Email us at [security@stripe.com](mailto:security@stripe.com)

GitHub advisory

Affected versions

PackageAffectedFixed in
vscode-stripe
Product
< 1.7.31.7.3
Details and references
CVSS 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
Severity from
GitHub (reviewed advisory)

More Stripe advisories

All Stripe
Advisory
Vulnerability in stripe-cli >= 1.11.1
High7.5Sep 5, 2024
Smokescreen SSRF via deny list bypass (square brackets)
Medium5.3May 10, 2022
Smokescreen SSRF via deny list bypass
Medium5.8Apr 7, 2022
Vulnerability in Stripe CLI < 1.7.13
MediumMar 9, 2022

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.