A security feature bypass vulnerability exists in VS Code 1.128.0 and earlier versions where, under certain conditions, specially crafted notebook content could bypass security restrictions in Restricted Mode.
Patches
The fix is available starting with VS Code 1.128.1. The fix mitigates this attack by improving how untrusted notebook content is handled.
Workarounds
Do not open notebooks from untrusted sources on versions of VS Code <=1.128.0.
References
A security feature bypass vulnerability exists in VS Code 1.128.0 and earlier versions where, under certain conditions, specially crafted notebook content could bypass security restrictions in Restricted Mode.
Patches
The fix is available starting with VS Code 1.128.1. The fix mitigates this attack by improving how untrusted notebook content is handled.
Workarounds
Do not open notebooks from untrusted sources on versions of VS Code <=1.128.0.
References