The Lab · 2026-03-28 00:27:02 · GitHub Issues
A critical security flaw in Microsoft's VS Code Copilot Chat extension allowed attackers to bypass its core 'sensitive file' approval mechanism, potentially leading to remote code execution. The vulnerability, present in versions 0.37.2 and earlier, centers on the `apply_patch` function. An attacker could use a prompt-...
The Lab · 2026-03-28 00:27:03 · GitHub Issues
A critical remote code execution vulnerability has been disclosed in Microsoft's VS Code Copilot Chat, exposing users to potential compromise through a sophisticated prompt injection attack. The flaw, present in versions 0.37.2 and earlier, allows a maliciously manipulated AI agent to trick users into opening or fetchi...
The Lab · 2026-03-28 00:27:05 · GitHub Issues
A critical vulnerability in Microsoft's Visual Studio Code (VS Code) editor allowed commands to be automatically and repeatedly executed across different workspaces, effectively enabling cross-workspace code execution. The flaw, present in VS Code version 1.109 and earlier, resided in the `terminal.integrated.autoRepli...
The Lab · 2026-03-28 01:26:56 · GitHub Issues
A critical security vulnerability in the Ruby-LSP extension for VS Code has been patched, exposing developers to arbitrary code execution simply by opening a malicious project. The flaw, tracked as CVE-2026-34060, resided in the handling of the `rubyLsp.branch` workspace setting. This setting was interpolated without s...
The Lab · 2026-04-13 12:53:00 · Habr
Подключение десятков MCP-серверов к ИИ-агенту в VS Code привело к шокирующим счетам за API и замусоренным системным промптам. Разработчик столкнулся с классической проблемой: каждый новый сервер — от баз данных до OpenAPI-каталогов — увеличивал стоимость вызовов и провоцировал галлюцинации у языковых моделей. Вместо то...
The Lab · 2026-05-12 17:48:25 · GitHub Issues
A remote code execution vulnerability has been identified in VS Code versions 1.119.0 and earlier, specifically targeting the webview component used by Jupyter notebooks. The flaw stems from an incorrect buffer allocation in the internal protocol that webviews employ to load VS Code-controlled root content, allowing at...