PT-2025-44215 · Microsoft+1 · Vscode+1
CVE-2025-62794
·
Publicado
2025-10-28
·
Atualizado
2025-10-29
CVSS v3.1
3.8
Baixa
| Vetor | AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
GitHub Workflow Updater versions prior to 0.0.7
Description
The GitHub Workflow Updater VS Code extension had a security issue where GitHub tokens were stored in plaintext within the editor configuration as JSON on disk, instead of utilizing the secure storage API. This meant an attacker with read access to a user's home directory could potentially access the token and use it to perform actions.
Recommendations
Update to version 0.0.7.
Exploit
Correção
Insufficiently Protected Credentials
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Github Workflow Updater
Vscode