GitHubCredentialProvider - Regex substring host match sends Basic-auth tokens
HighCVE-2026-47284 · Published Jun 9, 2026
### Impact A security feature bypass vulnerability exists in VS Code's built-in GitHub extension, where `GitHubCredentialProvider` validated the request host using the unanchored regex `/github\.com/i`. Because the pattern is a substring match (no `^`/`
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| vscode Product | < 1.123.1 | 1.123.1 |
Details and references
### Impact A security feature bypass vulnerability exists in VS Code's built-in GitHub extension, where `GitHubCredentialProvider` validated the request host using the unanchored regex `/github\.com/i`. Because the pattern is a substring match (no `^`/`
- Severity from
- GitHub (reviewed advisory)
More Microsoft advisories
All Microsoft| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Jul 2 | Microsoft 365 Copilot: open redirect | Critical9.3 | No fix yet |
| Jul 2 | Microsoft Azure Synapse: improper access control | Medium4.8 | No fix yet |
| Jul 1 | Microsoft Edge (Chromium-based): use after free | High8.3 | 149.0.4022.68 |
| Jun 9 | Path traversal in profile snippets import allows writing files outside the profile directory (Zip-Slip) | Medium | 1.123.1 |
| Jun 9 | Auto-Approved File Write via Unconfirmed Environment-Variable Path Redirection | Low | 1.123.1 |
| Jun 9 | Unconfirmed Remote Host Connection via Workspace File | High | 1.123.1 |
Critical advisories by email
Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.