🗾較早收集於 68m

VS Code擴充套件4件重大漏洞,累計下載12億

VS Code擴充套件4件重大漏洞,累計下載12億
PostLinkedIn
🗾閱讀原文: ITmedia AI+ (日本)
#rce#supply-chain#dev-toolsvs-code-extensions

💡1.2B-download VS Code extensions have RCE vulns—affecting Cursor—check your setup now!

⚡ 30-Second TL;DR

有什麼變化

4款VS Code擴充套件存RCE與檔案外洩等重大漏洞

為什麼重要

數百萬開發者面臨供應鏈風險,可能危害AI開發流程。凸顯熱門工具漏洞,促請立即修補與生態改善。

下一步行動

Audit your VS Code extensions for Live Server and disable any of the 4 vulnerable ones immediately.

誰應關注:Developers & AI Engineers

關鍵要點

  • 4款VS Code擴充套件存RCE與檔案外洩等重大漏洞
  • 受影響包括Live Server等,總下載12億次
  • 波及Cursor等AI編碼工具,呼籲強化擴充審核

🧠 深度解析

背景與延伸:來自公開資料,非原文內容。引用 9 個來源。

🔑 增強重點摘要

  • OX Security disclosed critical vulnerabilities in four VS Code extensions—Live Server (CVE-2025-65717, CVSS 9.1, 72M+ downloads), Code Runner (CVE-2025-65715, CVSS 7.8, 37M downloads), Markdown Preview Enhanced (CVE-2025-65716, CVSS 8.8, 8.5M downloads), and Microsoft Live Preview (no CVE, 11M+ downloads)—totaling over 125-128 million installs, enabling file exfiltration, RCE, and network reconnaissance[1][2][3][4][5].
  • Exploits rely on social engineering: tricking developers into visiting malicious websites while extensions run localhost servers (e.g., Live Server at port 5500), opening crafted Markdown files, or applying malicious settings.json configs[1][2][3][4][5].
  • Vulnerabilities affect VS Code, Cursor, and Windsurf AI IDEs; three remain unpatched as maintainers did not respond to disclosures since June 2025, while Microsoft silently fixed Live Preview in v0.4.16 (September 2025)[1][3][4][5].
  • Attack tactics include TA0009 (Collection), TA0007 (Discovery), TA0002 (Execution), risking theft of API keys, configs, and network pivoting[2][3].
  • Mitigations: Disable unnecessary extensions, avoid untrusted links/configs/Markdown while servers run, update regularly, firewall localhost, monitor settings[3][4].

🛠️ 技術深入

CVE-2025-65717 (Live Server v5.7.9): Malicious webpage JavaScript interacts with localhost:5500 HTTP server to recursively enumerate and exfiltrate files[1][2][8].

  • CVE-2025-65715 (Code Runner): Social engineering alters settings.json to execute arbitrary commands[2][3].
  • CVE-2025-65716 (Markdown Preview Enhanced): Malicious Markdown previews HTML/JS, scans local network ports, exfiltrates data[1][2][3].
  • Microsoft Live Preview (pre-0.4.16): One-click XSS via malicious site JS targeting localhost to enumerate/exfiltrate root files, credentials[1][3][4][5].

🔮 前景展望AI analysis grounded in cited sources

Exposes supply chain risks in dev tools, urging stricter VS Code extension reviews, sandboxing, and defenses for AI IDEs like Cursor; highlights need for rapid patching and awareness to prevent widespread developer machine compromises and data leaks.

時間線

2025-06
OX Security begins disclosing vulnerabilities to extension maintainers
2025-08
OX Security reports Live Preview issue to Microsoft
2025-09
Microsoft silently patches Live Preview in version 0.4.16
2026-02
OX Security publicly discloses the unpatched vulnerabilities
📰

AI 週報

閱讀本週精選 AI 大事摘要 →

👉相關動態

AI 策展新聞聚合。所有內容版權歸原始發布者所有。
原始來源: ITmedia AI+ (日本)

這是摘要,不是原文。去看原站,或訂閱每週簡報。

每週 AI 簡報

每週一封,可隨時退訂。