• Sources: primary, discussion
  • Summary: The post describes a link placed in a workspace file using the editor's command URI scheme, which on the plain source-editor path is rendered with the allowCommands argument set to a literal true, so clicking it invokes a command such as extension installation without Workspace Trust being consulted. The install step skips its own confirmation only when the target VSIX manifest declares support for untrusted workspaces, and that manifest is written by whoever ships the extension, so the attacker sets it. The researcher quotes the shipped _validateLink function, which tests only whether a link exceeds 50,000 characters, and contrasts that source-editor path with the webview path, which derives the same argument from an explicit opt-in added after CVE-2022-41034. The finding is single-sourced from a vendor blog, the researcher names no affected version and Microsoft has assigned no CVE, and the post states only that the technique works on the latest release and that Microsoft rated it moderate and declined an immediate hotfix, so the affected version range is not known.
  • Why it matters: Workspace Trust is the boundary that lets a developer open an unfamiliar repository at all, and on the plain source-editor path the editor never consults it, so cloning a repository and clicking one link is enough to run persistent code as the user.
  • Follow-up: Track a Microsoft fix, a CVE assignment, and independent confirmation of the quoted allowCommands literal against the VS Code repository.

send feedback on this story