Blog | G5 Cyber Security

Here’s how a researcher broke into Microsoft VS Code’s GitHub

A researcher has disclosed how he broke into the official GitHub repository of Microsoft Visual Studio Code. For responsibly reporting the vulnerability, the researcher was awarded a bug bounty award of an undisclosed amount. RyotaK discovered a vulnerability in the VS Code’s Continuous Integration (CI) script that could be exploited in code injection attacks. A flawed regex expression used to validate the closing comments and no authentication checks in the CI script meant, any user could associate a commit with an issue, and inject code within the closedWith value.

Source: https://www.bleepingcomputer.com/news/security/heres-how-a-researcher-broke-into-microsoft-vs-codes-github/

Exit mobile version