PT-2025-44215 · Microsoft+1 · Vscode+1

CVE-2025-62794

·

Publicado

2025-10-28

·

Atualizado

2025-10-29

CVSS v3.1

3.8

Baixa

VetorAV:L/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions GitHub Workflow Updater versions prior to 0.0.7
Description The GitHub Workflow Updater VS Code extension had a security issue where GitHub tokens were stored in plaintext within the editor configuration as JSON on disk, instead of utilizing the secure storage API. This meant an attacker with read access to a user's home directory could potentially access the token and use it to perform actions.
Recommendations Update to version 0.0.7.

Exploit

Correção

Insufficiently Protected Credentials

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2025-62794
GHSA-679X-97JW-8VJP

Produtos afetados

Github Workflow Updater
Vscode