Home
Home
Trends
Trends
Vulnerabilities
Vulnerabilities
News
News
Researchers
Researchers
Why dbugs?
Why dbugs?
Settings

Adityasharad

#34235of 56,330
7.8Total CVSS
Vulnerabilities · 1
PT-2019-14821
7.8
2019-11-25
Github · Codeql · CVE-2019-16765
**Name of the Vulnerable Software and Affected Versions** CodeQL extension versions prior to 1.0.1 **Description** The issue allows an attacker to execute arbitrary code on a user's system if the user opens a specially prepared directory tree as a workspace in Visual Studio Code with the CodeQL extension active. **Recommendations** For versions prior to 1.0.1, upgrade to version 1.0.1 of the CodeQL extension using Visual Studio Code Marketplace's upgrade mechanism. After upgrading, ensure the codeQL.cli.executablePath setting is only set in the per-user settings.