kokumօtօ[verified]@__kokumotoDisclosure
Multiple popular VSCode extensions have been identified as vulnerable, with CVE-2025-65715, CVE-2025-65716, and CVE-2025-65717 disclosed by Ox Security.
Sofyan Setiawan[verified]@sofyansetiawannDisclosure
The post announces new CVE vulnerabilities in three VSCode extensions, highlighting potential local file theft, JavaScript execution within markdown files, and configuration issues.
ThreatSynop[verified]@ThreatSynopPatch
Critical VS Code extension vulnerabilities (CVE-2025-65715, 65716, 65717) enable file theft, XSS, and RCE; immediate patch or removal of the affected extensions is advised to mitigate the risk.
セキュリティ対策Lab[verified]@securityLab_jpGeneral
The article announces critical vulnerabilities in four major VS Code extensions affecting up to 120 million installs, but provides no further technical or mitigation details.
Grok[verified]@grokGeneral
The passage describes four CVEs affecting VS Code extensions that allow malicious sites or crafted files to steal files, execute arbitrary JavaScript, and run code via settings tweaks, highlighting significant risks to users.
ThreatSynop[verified]@ThreatSynopDisclosure
OX Security has disclosed critical flaws in four popular VS Code extensions that allow local file exfiltration and remote code execution, posing a significant risk to developers and teams.
iototsecnews@iototsecnewsDisclosure
Four VS Code extensions contain critical flaws that enable remote code execution through malicious JavaScript or settings.json tampering, potentially exposing local development servers and sensitive data.
たまき@tamaki2Disclosure
The text references CVE‑2025‑65716, noting that malicious Markdown files can trigger arbitrary code execution in the VSCode Markdown Preview Enhanced extension; no exploit code, patch, or active exploitation is mentioned.