VS Code擴充套件4件重大漏洞,累計下載12億

💡1.2B-download VS Code extensions have RCE vulns—affecting Cursor—check your setup now!
⚡ 30-Second TL;DR
有什麼變化
4款VS Code擴充套件存RCE與檔案外洩等重大漏洞
為什麼重要
數百萬開發者面臨供應鏈風險,可能危害AI開發流程。凸顯熱門工具漏洞,促請立即修補與生態改善。
下一步行動
Audit your VS Code extensions for Live Server and disable any of the 4 vulnerable ones immediately.
關鍵要點
- •4款VS Code擴充套件存RCE與檔案外洩等重大漏洞
- •受影響包括Live Server等,總下載12億次
- •波及Cursor等AI編碼工具,呼籲強化擴充審核
🧠 深度解析
背景與延伸:來自公開資料,非原文內容。引用 9 個來源。
🔑 增強重點摘要
- •OX Security disclosed critical vulnerabilities in four VS Code extensions—Live Server (CVE-2025-65717, CVSS 9.1, 72M+ downloads), Code Runner (CVE-2025-65715, CVSS 7.8, 37M downloads), Markdown Preview Enhanced (CVE-2025-65716, CVSS 8.8, 8.5M downloads), and Microsoft Live Preview (no CVE, 11M+ downloads)—totaling over 125-128 million installs, enabling file exfiltration, RCE, and network reconnaissance[1][2][3][4][5].
- •Exploits rely on social engineering: tricking developers into visiting malicious websites while extensions run localhost servers (e.g., Live Server at port 5500), opening crafted Markdown files, or applying malicious settings.json configs[1][2][3][4][5].
- •Vulnerabilities affect VS Code, Cursor, and Windsurf AI IDEs; three remain unpatched as maintainers did not respond to disclosures since June 2025, while Microsoft silently fixed Live Preview in v0.4.16 (September 2025)[1][3][4][5].
- •Attack tactics include TA0009 (Collection), TA0007 (Discovery), TA0002 (Execution), risking theft of API keys, configs, and network pivoting[2][3].
- •Mitigations: Disable unnecessary extensions, avoid untrusted links/configs/Markdown while servers run, update regularly, firewall localhost, monitor settings[3][4].
🛠️ 技術深入
CVE-2025-65717 (Live Server v5.7.9): Malicious webpage JavaScript interacts with localhost:5500 HTTP server to recursively enumerate and exfiltrate files[1][2][8].
- CVE-2025-65715 (Code Runner): Social engineering alters settings.json to execute arbitrary commands[2][3].
- CVE-2025-65716 (Markdown Preview Enhanced): Malicious Markdown previews HTML/JS, scans local network ports, exfiltrates data[1][2][3].
- Microsoft Live Preview (pre-0.4.16): One-click XSS via malicious site JS targeting localhost to enumerate/exfiltrate root files, credentials[1][3][4][5].
🔮 前景展望AI analysis grounded in cited sources
Exposes supply chain risks in dev tools, urging stricter VS Code extension reviews, sandboxing, and defenses for AI IDEs like Cursor; highlights need for rapid patching and awareness to prevent widespread developer machine compromises and data leaks.
⏳ 時間線
📎 來源 (9)
Factual claims are grounded in the sources below. Forward-looking analysis is AI-generated interpretation.
- infosecurity-magazine.com — Vulnerabilities vs Code Cursor
- secpod.com — Supply Chain Risk Critical Flaws Identified in Popular vs Code Extensions
- bleepingcomputer.com — Flaws in Popular Vscode Extensions Expose Developers to Attacks
- thehackernews.com — Critical Flaws Found in Four vs Code
- csoonline.com — Flaws in Four Popular vs Code Extensions Left 128 Million Installs Open to Attack
- esecurityplanet.com — Xss Bug in vs Code Extension Exposed Local Files
- socradar.io — Vs Code Extension Cves Rce
- nvd.nist.gov — Cve 2025 65717
- britec.com — 7175
AI 週報
閱讀本週精選 AI 大事摘要 →
👉相關動態
AI 策展新聞聚合。所有內容版權歸原始發布者所有。
原始來源: ITmedia AI+ (日本) ↗
每週 AI 簡報
每週一封,可隨時退訂。
