#VU27812 Input validation error in Visual Studio Code Python Extension - CVE-2020-1171
Published: May 12, 2020
Visual Studio Code Python Extension
Microsoft
Description
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists in the Visual Studio Code when the Python extension loads configuration files after opening a project. A remote attacker can trick a victim to clone a repository and open it in Visual Studio Code with the Python extension installed.
Attacker-specified code would execute when the target opened the integrated terminal.