High severity7.8NVD Advisory· Published Mar 18, 2021· Updated Jun 17, 2026
CVE-2021-28789
CVE-2021-28789
Description
The unofficial apple/swift-format extension before 1.1.2 for Visual Studio Code allows remote attackers to execute arbitrary code by constructing a malicious workspace with a crafted apple-swift-format.path configuration value that triggers execution upon opening the workspace.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
4- Visual Studio Code/apple/swift-formatdescription
- cpe:2.3:a:apple-swift-format_project:apple-swift-format:*:*:*:*:*:visual_studio:*:*Range: <1.1.2
- Range: <1.1.2
- Range: <1.1.2
Patches
Vulnerability mechanics
References
2- github.com/vknabel/vscode-apple-swift-format/releases/tag/1.1.2nvdRelease NotesThird Party Advisory
- vuln.ryotak.me/advisories/11nvdThird Party Advisory
News mentions
0No linked articles in our index yet.