High severity8.8NVD Advisory· Published Mar 31, 2021· Updated Jun 17, 2026
CVE-2021-29658
CVE-2021-29658
Description
The unofficial vscode-rufo extension before 0.0.4 for Visual Studio Code allows attackers to execute arbitrary binaries if the user opens a crafted workspace folder.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3- Range: <0.0.4
- Range: <0.0.4
- cpe:2.3:a:vscode-rufo_project:vscode-rufo:*:*:*:*:*:visual_studio:*:*Range: <0.0.4
Patches
Vulnerability mechanics
References
3- github.com/jnbt/vscode-rufo/commit/bc0d212436f76d12cbdab287802fa5bc743f818anvdPatchThird Party Advisory
- marketplace.visualstudio.com/items/jnbt.vscode-rufo/changelognvdRelease NotesThird Party Advisory
- vuln.ryotak.me/advisories/8nvdThird Party Advisory
News mentions
0No linked articles in our index yet.