CVE-2023-36867: Visual Studio Code GitHub Pull Requests and Issues Extension Remote Code Execution Vulnerability
Visual Studio Code GitHub Pull Requests and Issues Extension Remote Code Execution Vulnerability
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 0.66.2
Event History
Frequently Asked Questions
What is CVE-2023-36867 vulnerability?
CVE-2023-36867 is a Visual Studio Code GitHub Pull Requests and Issues Extension Remote Code Execution Vulnerability.
How severe is CVE-2023-36867 vulnerability?
CVE-2023-36867 vulnerability has a severity level of high (7).
What software is affected by CVE-2023-36867 vulnerability?
The Visual Studio Code GitHub Pull Requests and Issues Extension version 0.66.2 and prior are affected by CVE-2023-36867 vulnerability.
How can I fix CVE-2023-36867 vulnerability?
To fix CVE-2023-36867 vulnerability, update the Visual Studio Code GitHub Pull Requests and Issues Extension to a version higher than 0.66.2.
Where can I find more information about CVE-2023-36867 vulnerability?
You can find more information about CVE-2023-36867 vulnerability at the Microsoft Security Response Center (MSRC) website.