Remote Code Execution Vulnerability
HighCVE-2023-36742 · Published Sep 12, 2023
A remote code execution vulnerability exists in VS Code 1.82.0 and earlier versions that working in a maliciously crafted `package.json` can result in executing commands locally. This scenario would require the attacker to get the VS Code user to open the malicious project and have get the user to open and work with malformed entries in the dependencies sections of the `package.json` file. VS Code uses the locally installed `npm` command to fetch information on package dependencies. A package dependency can be named in such a way that the `npm` tool runs a script instead. ### Patches The fix is available starting with **VS Code 1.82.1**. The fix (https://github.com/microsoft/vscode/commit/e7b339721792056cee11c11afc69df71a0a85d59) mitigates this attack by turning off the usage of `npm` in an untrusted workspace and by adding extra input validation when calling the npm command. ### Workarounds Do not work with the dependencies sections in the `package.json` file that originate from an untrusted source. ### References * The patch for this can be found at https://github.com/microsoft/vscode/commit/e7b339721792056cee11c11afc69df71a0a85d59 * An issue for this can be found at https...
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| vscode Product | < 1.82.1 | 1.82.1 |
Details and references
A remote code execution vulnerability exists in VS Code 1.82.0 and earlier versions that working in a maliciously crafted `package.json` can result in executing commands locally. This scenario would require the attacker to get the VS Code user to open the malicious project and have get the user to open and work with malformed entries in the dependencies sections of the `package.json` file. VS Code uses the locally installed `npm` command to fetch information on package dependencies. A package dependency can be named in such a way that the `npm` tool runs a script instead. ### Patches The fix is available starting with **VS Code 1.82.1**. The fix (https://github.com/microsoft/vscode/commit/e7b339721792056cee11c11afc69df71a0a85d59) mitigates this attack by turning off the usage of `npm` in an untrusted workspace and by adding extra input validation when calling the npm command. ### Workarounds Do not work with the dependencies sections in the `package.json` file that originate from an untrusted source. ### References * The patch for this can be found at https://github.com/microsoft/vscode/commit/e7b339721792056cee11c11afc69df71a0a85d59 * An issue for this can be found at https://github.com/microsoft/vscode/issues/192906 * MSRC details for this can be found at https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-36742
- Severity from
- GitHub (reviewed advisory)
More Microsoft advisories
All Microsoft| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Mar 122024 | Elevation of Privilege Vulnerability | High8.8 | 1.87.2 |
| Sep 122023 | Remote Code Execution Vulnerability | High | 1.80.2 |
| Jun 132023 | Information Disclosure Vulnerability | High | 1.79.1 |
| May 92023 | Information Disclosure Vulnerability | High | 1.78.1 |
| Apr 112023 | Remote Code Execution Vulnerability | High | 1.77.1 |
| Jan 102023 | Remote Code Execution Vulnerability | Medium | 1.74.3 |