CVE-2021-29261
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
05/04/2021
Last modified:
08/04/2021
Description
The unofficial Svelte extension before 104.8.0 for Visual Studio Code allows attackers to execute arbitrary code via a crafted workspace configuration.
Impact
Base Score 3.x
7.80
Severity 3.x
HIGH
Base Score 2.0
6.80
Severity 2.0
MEDIUM
Vulnerable products and versions
CPE | From | Up to |
---|---|---|
cpe:2.3:a:svelte:svelte:*:*:*:*:*:visual_studio_code:*:* | 104.8.0 (excluding) |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- https://github.com/sveltejs/language-tools/commit/5d7bf1fd98bfe2cd2080863a3c95ce099b898075
- https://github.com/sveltejs/language-tools/releases
- https://github.com/sveltejs/language-tools/releases/tag/extensions-104.8.0
- https://marketplace.visualstudio.com/items?itemName=svelte.svelte-vscode
- https://vuln.ryotak.me/advisories/3