Gallery

Contacts

405 W. Greenlawn Ave Lansing, Michigan 48910

contact@techjacksolutions.com

+1-616-320-4064

A publicly disclosed, unpatched zero-day in Visual Studio Code allows an attacker to steal a developer’s GitHub OAuth token with a single click on a malicious link. The stolen token grants full access to every private GitHub repository the victim can reach, inheriting the full permission scope of the victim’s GitHub account. No patch is available from Microsoft, a working exploit is publicly circulating, and no CVE has been assigned, meaning automated vulnerability scanners will not flag this exposure.

Author

Tech Jacks Solutions