CVE-2021-29261: High severity sveltekit vulnerability
Published Apr 5, 2021
·Updated
The unofficial Svelte extension before 104.8.0 for Visual Studio Code allows attackers to execute arbitrary code via a crafted workspace configuration.
Affected Software
1 affected component
svelte Svelte Visual Studio Code<104.8.0
Remediation
Event History
Apr 5, 2021
CVE Published
via MITRE·06:15 AM
Data Sourced
via MITRE·06:15 AM
Description
Frequently Asked Questions
1
What is CVE-2021-29261?
CVE-2021-29261 is a vulnerability in the unofficial Svelte extension before version 104.8.0 for Visual Studio Code.
2
How severe is CVE-2021-29261?
CVE-2021-29261 has a severity score of 7.8, which is considered high.
3
How can attackers exploit CVE-2021-29261?
Attackers can execute arbitrary code by exploiting CVE-2021-29261 through a crafted workspace configuration.
4
Which software is affected by CVE-2021-29261?
The unofficial Svelte extension before version 104.8.0 for Visual Studio Code is affected by CVE-2021-29261.
5
How to fix CVE-2021-29261?
To fix CVE-2021-29261, it is recommended to update to version 104.8.0 or later of the unofficial Svelte extension for Visual Studio Code.