VS Code 1.136.2 fixes RCE via remote agent host settings
Malicious workspace settings in untrusted repos could authorize a remote agent and expose local files.
By renderMalicious workspace settings in untrusted repos could authorize a remote agent and expose local files.
By renderGNOME Remote Desktop and KDE krdp embeds are in scope when an administrator has enabled the service; client-only FreeRDP is not.
By tarpitDefault unauthenticated Gremlin Server plus a Groovy sandbox bypass lets remote attackers run OS commands as the dse user.
By staffA public advisory shows how default open ksqlDB, Kafka, and Connect endpoints chain into cron-based root execution with no credentials.
By staffThree important-severity flaws let DAG authors run code in components Airflow’s security model says must stay clean of author-controlled execution.
By tarpitCVE-2026-59113 let a crafted page drive OS protocol handlers and premature extension URL overrides when users fetched untrusted content.
By renderUnauthenticated attackers can leak server secrets, and potentially escalate to RCE, on apps using libvips with untrusted uploads.
By nonceA single DNS-over-QUIC connection could overflow a heap buffer; the flaw is fixed in 6.4.1.
By tarpit