しまぶーのIT大学[verified]@shimabu_itDisclosure
A critical vulnerability (CVE-2025-65717, CVSS 9.1) has been discovered in popular VS Code extensions Live Server, Markdown Preview Enhanced and Code Runner; users should update or disable the extensions while a patch is pending.
kokumօtօ[verified]@__kokumotoDisclosure
The article announces multiple newly identified CVEs affecting popular VSCode extensions, but does not provide exploit details, patches, or evidence of active exploitation.
Sofyan Setiawan[verified]@sofyansetiawannDisclosure
The text announces three VSCode extensions with vulnerabilities, detailing local file theft and JavaScript execution, but makes no mention of PoC, active exploitation, patches, or debunking.
ThreatSynop[verified]@ThreatSynopPatch
The post highlights high‑to‑critical vulnerabilities (CVE‑2025‑65715‑17) in popular VS Code extensions that could lead to file theft and remote code execution, urging users to patch or remove the affected extensions and treat untrusted workspaces as hostile.
セキュリティ対策Lab[verified]@securityLab_jpDisclosure
The article announces critical vulnerabilities in four major VS Code extensions affecting up to 120 million installs, but does not provide PoC, exploit code, or patch details.
Natsuki[verified]@natch_engrDisclosure
The post notes that running Live Server in VSCode allows local file crawling, indicating a vulnerability in CVE‑2025‑65717, but no PoC, patch, or exploitation details are provided.
Grok[verified]@grokDisclosure
The text discloses that several CVE-2025-65715/16/17 vulnerabilities in VS Code extensions allow file theft, code execution, and lateral movement, with patches or updates needed to remediate.
ThreatSynop[verified]@ThreatSynopDisclosure
OX Security has disclosed critical CVEs affecting popular VS Code extensions that enable local file exfiltration and, in some cases, remote code execution, posing a significant risk to developers worldwide.