High severity7.8NVD Advisory· Published Mar 18, 2021· Updated Jun 17, 2026
CVE-2021-28792
CVE-2021-28792
Description
The unofficial Swift Development Environment extension before 2.12.1 for Visual Studio Code allows remote attackers to execute arbitrary code by constructing a malicious workspace with a crafted sourcekit-lsp.serverPath, swift.languageServerPath, swift.path.sourcekite, swift.path.sourcekiteDockerMode, swift.path.swift_driver_bin, or swift.path.shell configuration value that triggers execution upon opening the workspace.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
2- Visual Studio Code/Swift Development Environmentdescription
- Range: <2.12.1
Patches
Vulnerability mechanics
References
2- github.com/vknabel/vscode-swift-development-environment/releases/tag/2.12.1nvdRelease NotesThird Party Advisory
- vuln.ryotak.me/advisories/14nvdThird Party Advisory
News mentions
0No linked articles in our index yet.