7.8
CVSSv3

CVE-2021-26700

Published: 25/02/2021 Updated: 29/12/2023
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
CVSS v3 Base Score: 7.8 | Impact Score: 5.9 | Exploitability Score: 1.8
VMScore: 606
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

Visual Studio Code npm-script Extension Remote Code Execution Vulnerability

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

microsoft visual studio code npm-script extension

Github Repositories

RCE in NPM VSCode Extension

RCE in NPM VSCode Extension Fixed 10th February 2021 in githubcom/microsoft/vscode-npm-scripts/commit/cdd5e507564e0cc0f60bcccf184822be3fd73e07 msrcmicrosoftcom/update-guide/vulnerability/CVE-2021-26700 Summary Remote code execution vulnerability in the eg2vscode-npm-script (Tested on version 0313) VSCode extension means that a malicious vscode/settingsjs

CVE-2021-26700 (Note: this manual is valid for DSNS lab's members only) Intruduction This is a remote code execution (RCE) vulnerability that resided in an extension of Visual Studio Code (VS Code) called npm, which was developed by Microsoft and was aimed to support running the npm scripts defined in the packagejson file To exploit this vulnerability, the attacker migh