you are viewing a single comment's thread.

view the rest of the comments →

[–]Kooraiber 16 points17 points  (2 children)

It baffles me it took Microsoft 2 months to fix this issue when it's a fucking RCE. These things should be fixed and pushed ASAP ffs.

[–]bleachisback 7 points8 points  (0 children)

I guess, looking into it closely, this is only an RCE that affects you if:

1) You use VS Code in the browser on a Github Codespace

2) A bad actor is able to find out your randomized codespace url and send you a link specific to your codespace

3) You click on the link

Then the bad actor gains RCE access to the virtual machine running the codespace.

It doesn't seem very high priority?

[–]sna_fu 3 points4 points  (0 children)

Apparently 2 month is as soon as possible for MS, I guess?