ended6월 3일· 1 sources

github.dev / VSCode Web에서 링크 클릭만으로 GitHub 토큰이 탈취될 수 있는 취약점

Why it matters

A critical vulnerability in github.dev and VSCode Web allows attackers to steal GitHub tokens through a single malicious link, exploiting Jupyter Notebook JavaScript execution combined with VSCode extension installation mechanisms. This directly threatens millions of developers relying on these tools, making immediate awareness and defensive measures essential to prevent unauthorized repository access.

1
Sources
+0
24h
Growth
110d
Active
github.devVSCode WebToken theftWebview vulnerabilityJupyter NotebookVSCode Extension

Sources

Related Issues