BTC $71,807
2026 Bull Run Is Building Start trading with 5% OFF all fees
Sign Up Now
BTC $71,807
Bull Run 2026 | 5% Off Fees Open your Binance account today
Sign Up

GitHub Token Theft Via VSCode Web Vulnerability

One-click exploit steals GitHub token via VS Code web editor vulnerability.

  • A critical vulnerability in Microsoft Visual Studio Code’s GitHub.dev web editor allows attackers to steal a user’s full-access GitHub token with a single click.
  • The exploit uses malicious JavaScript to install an attacker-controlled extension, bypassing security checks to access and potentially write to all of a user’s repositories.
  • Microsoft has acknowledged the flaw and is working on a fix, but the issue does not affect the VS Code Desktop application.

Cybersecurity researchers disclosed on June 3, 2026, a severe one-click attack vector in Microsoft Visual Studio Code’s GitHub.dev web editor. This vulnerability directly threatens the security of developers’ private code repositories.

- Advertisement -

“Just by clicking a link, it’s possible for an attacker to steal a GitHub token that can read and write to your repos, including private ones,” security researcher Ammar Askar said. The token provides full access instead of being scoped to a single project.

The attack exploits a message-passing mechanism between the main editor and its webviews. Consequently, malicious JavaScript can simulate keypresses to open the Command Palette and install a rogue extension.

This extension then steals the GitHub OAuth token passed to the web-based editor. It can subsequently query the GitHub API to enumerate all accessible private repositories.

The exploit leverages a feature called local workspace extensions to bypass publisher trust checks. This allows installation directly from a workspace folder without security prompts.

- Advertisement -

Microsoft was notified of the vulnerability on June 2, 2026. Details were made public shortly thereafter, citing the company’s past handling of similar bugs.

“To clarify, this issue does not affect VS Code Desktop,” said Alexandru Dima, a partner software engineering manager at Microsoft. Meanwhile, the company has acknowledged the report and noted it is working on a fix.

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

Previous Articles:

- Advertisement -
Ad
Altseason Is Loading. Don't watch from the sidelines.
SOL $90.51
DOGE $0.0963
LINK $9.02
SUI $1.00
5% off fees when you sign up
Start Trading
Ad
Pay Less on Every Trade. For Life.
$10K/mo volume Save $60/yr
$50K/mo volume Save $300/yr
$100K/mo volume Save $600/yr
5% off all trading fees when you sign up
Claim Your Discount

Latest News

Visa, Mastercard, Stripe Launch Joint Stablecoin

Payment giants VISA, Mastercard, and Stripe are jointly developing a new stablecoin likely pegged...

U.S. Sanctions Iranian Crypto Exchanges Over $40B in Flows

The US Treasury has sanctioned Nobitex, Wallex, Bitpin, and Ramzinex—Iran's four largest cryptocurrency exchanges—alongside...

Critical Zcash Bug Patched in Emergency Upgrade, ZEC Up 50%

A critical bug in ZCash's Orchard privacy pool could have enabled double-spending, but was...

FCA warns Premier League clubs over crypto sponsorships

The FCA warns Premier League clubs about money laundering risks from crypto sponsorships.Fans risk...

Mastercard Adopts Stablecoins for Card Settlements

Mastercard will allow its partners to settle card transactions using regulated stablecoins on multiple...

Must Read

What Is the Dencun Upgrade for Ethereum?

The Dencun Upgrade for Ethereum is poised to revolutionize the blockchain landscape, offering improved scalability, efficiency, and groundbreaking features. Set to launch at the...
Ad
Altseason Is Loading. These 4 coins are trending right now.
SOL $92.12
DOGE $0.0950
LINK $9.02
SUI $1.02
5% off spot fees when you sign up
Start Trading