
💎 Malicious VS Code repo can trigger code execution via Ruby LSP CVE-2026-48122 affects the Ruby LSP VS Code extension before 0.10.4. A malicious repository containing crafted .vscode/settings.json settings can redirect Ruby/Bundler executable paths. If a developer trusts and opens the repository, attacker-controlled code can execute with the developer's privileges. ✅ Fixed in 0.10.4. 🔎 Source: GitHub / CVE / VulDB #Ruby #VSCode #SupplyChain #CVE #CyberSecurity
Post summary
CVE-2026‑48122 allows code execution via a malicious VS Code repo by redirecting Ruby/Bundler paths in Ruby LSP, and the issue has been fixed in version 0.10.4.

