HIGH
CVE-2021-22195
CVSS
7.8
Description
Client side code execution in gitlab-vscode-extension v3.15.0 and earlier allows attacker to execute code on user system
Summary dbcve.org
The GitLab VSCode extension before version 3.15.0 contains a client-side code execution vulnerability. An attacker could potentially craft malicious content (such as issues, merge requests, or other GitLab resources) that, when opened by a user with the vulnerable extension installed, would allow arbitrary code execution on the user's local system.
Mitigation
Upgrade the GitLab VSCode extension to a version newer than 3.15.0. Users should update immediately as this vulnerability can be triggered simply by opening malicious GitLab content.
Weakness (CWE)
CWE-427
Uncontrolled Search Path (DLL Hijack)
EPSS Score
1.14%
Probability of exploitation in next 30 days
65.2th percentile
References
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.