ended6월 3일· 1 sources
One Click Away: Critical VSCode Flaw Exposes Your GitHub Credentials
VSCode github.dev, 한 클릭으로 모든 GitHub 저장소 접근 가능한 치명적 결함
Why it matters
The vulnerability targets developers using VSCode's browser-based github.dev tool, which runs with GitHub OAuth tokens that have unrestricted access to all user repositories, including private ones. An attacker can steal these tokens with a single click by exploiting a flaw in VSCode's webview sandbox model, immediately gaining full repository access. This incident highlights how OAuth overpermissioning combined with browser sandbox bypasses can create critical security risks in developer-focused tools.
1
Sources
+0
24h
—
Growth
6d
Active
VSCodegithub.devGitHub tokenWebview vulnerabilityOAuth scopeToken theft