#VU50500 Input validation error in Visual Studio Code npm-script Extension - CVE-2021-26700
Published: February 9, 2021 / Updated: November 17, 2021
Visual Studio Code npm-script Extension
Microsoft
Description
The vulnerability allows a remote attacker to execute arbitrary code on the system.
The vulnerability exists due to insufficient validation of user-supplied input in Visual Studio Code npm-script Extension. A remote attacker can trick a victim to clone a malicious repository and execute arbitrary code on the target system.