CVE-2025-62794
Gravedad CVSS v3.1:
BAJA
Tipo:
CWE-522
Credenciales insuficientemente protegidas
Fecha de publicación:
28/10/2025
Última modificación:
30/10/2025
Descripción
*** Pendiente de traducción *** GitHub Workflow Updater is a VS Code extension that automatically pins GitHub Actions to specific commits for enhanced security. Before 0.0.7, any provided Github token would be stored in plaintext in the editor configuration as json on disk, rather than through the more secure "securestorage" api. An attacker with read only access to your home directory could have read this token and used it to perform actions with that token. Update to 0.0.7.
Impacto
Puntuación base 3.x
3.80
Gravedad 3.x
BAJA



