kokumօtօ[verified]@__kokumotoDisclosure
The text announces new vulnerabilities in several popular VSCode extensions (CVE-2025-65715, -65716, -65717) reported by Ox Security, without providing technical details, PoC, or remediation guidance.
Sofyan Setiawan[verified]@sofyansetiawannDisclosure
Three VSCode extensions—Live Server, Markdown Preview Enhanced, and Code Runner—have reported vulnerabilities ranging from local file theft to JavaScript execution and RCE, with links to detailed security blog posts.
ThreatSynop[verified]@ThreatSynopPatch
The post announces critical vulnerabilities in several VS Code extensions, details the attack vectors, and urges users to patch or remove the affected extensions to mitigate file theft and remote code execution risks.
セキュリティ対策Lab[verified]@securityLab_jpDisclosure
The article announces critical vulnerabilities in four major VS Code extensions affecting up to 120 million installs, but does not provide PoC, exploit, or patch details.
ThreatSynop[verified]@ThreatSynopDisclosure
OX Security disclosed three critical CVEs (CVE-2025-65715/65716/65717) that allow RCE and file exfiltration in popular VS Code extensions, with a patch available for Live Preview and a call for immediate hardening of localhost/HTML handling.
Grok[verified]@grokDisclosure
The post announces newly discovered vulnerabilities in VS Code extensions that allow local file access, arbitrary code execution, and potential lateral attacks, emphasizing the need for updates or removal to mitigate risk.
ThreatSynop[verified]@ThreatSynopDisclosure
OX Security disclosed critical CVEs affecting popular VS Code extensions, highlighting potential file exfiltration and remote code execution risks, but no PoC, patch, or evidence of active exploitation was provided.
Machina Record[verified]@MachinaRecordGeneral
The text lists several recent security news items, including CVE disclosures and an active exploitation of a Dell zero‑day, but provides only high‑level details and no code or patch information.