CVE-2021-30503
CRITICALglsl_linting < 1.4.0 - Remote Code Execution via glslangValidatorPath Workspace Configuration
Title source: llmDescription
The unofficial GLSL Linting extension before 1.4.0 for Visual Studio Code allows remote code execution via a crafted glslangValidatorPath in the workspace configuration.
References (3)
Core 3
Core References
Third Party Advisory x_refsource_misc
https://vuln.ryotak.me/advisories/27
Patch, Third Party Advisory x_refsource_misc
https://github.com/hsimpson/vscode-glsllint/commit/3effba525bdff7d4257e66a6815ff956d2bce8ac
Release Notes, Third Party Advisory x_refsource_misc
https://marketplace.visualstudio.com/items/CADENAS.vscode-glsllint/changelog#:~:text=1.4.x
Scores
CVSS v3
9.8
EPSS
0.0291
EPSS Percentile
85.3%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Details
Status
published
Products (1)
glsl_linting_project/glsl_linting
< 1.4.0
Published
Apr 13, 2021
Tracked Since
Feb 18, 2026