
The CVE list is wild. - WebSocket auth bypass, any website could read your files via the IDE extension (CVE-2025-52882, CVSS 8.8) - Directory escape via naive prefix matching (CVE-2025-54794, CVSS 8.4) - Shell injection between whitelisted echo commands (CVE-2025-54795) - DNS exfiltration via command allowlist (CVE-2025-55284) 21 total. Growing.
Post summary
The message enumerates several high‑severity CVEs with concise technical characteristics but lacks any discussion of active exploitation, patches, or proof‑of‑concept material.

