Back to directory
WRITEUP #1509

Escaping well-configured VSCode extensions (for profit)

OtherElectronWebviewPath traversal
byVasco Franco
Bounty
7,500
Program
Microsoft
Published
Feb 23, 2023
Added to HackDex
Mar 8, 2023
Read Full Writeuphttps://blog.trailofbits.com/2023/02/23/escaping-well-configured-vscode-extensions-for-profit/
RELATED WRITEUPS
Oracle Retail Xstore Suite: Pre-authenticated Path Traversal
OtherPath traversal
Securing Developer Tools: Unpatched Code Vulnerabilities in Gogs (2/2)
OtherPath traversal
Data Theft in Salesforce: Manipulating Public Links
OtherSOQL injection
Directory Traversal, SQL Injection and Server-Side Request Forgery
SQL InjectionPath traversal
When Certificates Fail: A Story of Bypassed MFA in Remote Access
Other2FA / MFA bypass

Built with ❤️ by Shubham Rawat