EIP-2026-103783
PRE-CVEMicrosoft VSCode Python Extension - Code Execution
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-103783. PoCs published by Doyensec.
AI-analyzed exploit summary This is a technical writeup describing a code execution vulnerability in the VSCode Python extension, where VSCode may use code from a virtualenv in project folders without user consent, leading to arbitrary code execution. The PoC involves cloning a malicious repository and opening it in VSCode.
Description
Microsoft VSCode Python Extension - Code Execution
Exploits (1)
This is a technical writeup describing a code execution vulnerability in the VSCode Python extension, where VSCode may use code from a virtualenv in project folders without user consent, leading to arbitrary code execution. The PoC involves cloning a malicious repository and opening it in VSCode.