HIGH
CVE-2020-13279
CVSS
8.6
Description
Client side code execution in gitlab-vscode-extension v2.2.0 allows attacker to execute code on user system
Summary dbcve.org
Client-side code execution vulnerability in the GitLab VSCode Extension v2.2.0 allows an attacker to execute arbitrary code on a user's local system through the extension, likely via malicious content processed from GitLab repositories or communications.
Mitigation
Update the GitLab VSCode Extension to the latest patched version and audit systems for the vulnerable version.
Weakness (CWE)
CWE-427
Uncontrolled Search Path (DLL Hijack)
EPSS Score
1.2%
Probability of exploitation in next 30 days
66.8th percentile
References
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.