GHSA-fjmr-7667-8v4p

Suggest an improvement
Source
https://github.com/advisories/GHSA-fjmr-7667-8v4p
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/12/GHSA-fjmr-7667-8v4p/GHSA-fjmr-7667-8v4p.json
JSON Data
https://api.test.osv.dev/v1/vulns/GHSA-fjmr-7667-8v4p
Aliases
Published
2025-12-30T00:32:59Z
Modified
2025-12-31T22:26:13Z
Severity
  • 5.4 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:L CVSS Calculator
Summary
Visual Studio Code Go extension has unexpected untrusted code execution
Details

To prevent unexpected untrusted code execution, the Visual Studio Code Go extension is now disabled in Restricted Mode.

Database specific
{
    "cwe_ids":  [
        "CWE-94"
    ],
    "github_reviewed":  true,
    "github_reviewed_at":  "2025-12-31T22:05:05Z",
    "nvd_published_at":  "2025-12-30T00:15:52Z",
    "severity":  "MODERATE"
}
References

Affected packages

Go / github.com/golang/vscode-go

Package

Name
github.com/golang/vscode-go
View open source insights on deps.dev
Purl
pkg:golang/github.com/golang/vscode-go

Affected ranges

Type
SEMVER
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
0.52.1

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/12/GHSA-fjmr-7667-8v4p/GHSA-fjmr-7667-8v4p.json"