Critical severity9.0NVD Advisory· Published Aug 18, 2022· Updated Jun 17, 2026
CVE-2022-35975
CVE-2022-35975
Description
The GitOps Tools Extension for VSCode can make it easier to manage Flux objects. A specially crafted Flux object may allow for remote code execution in the machine running the extension, in the context of the user that is running VSCode. Users using the VSCode extension to manage clusters that are shared amongst other users are affected by this issue. The only safe mitigation is to update to the latest version of the extension.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3(expand)+ 1 more
- (no CPE)
- (no CPE)range: >= 0.7.0, <= 0.20.2
- cpe:2.3:a:weave:gitops_tools:*:*:*:*:*:visual_studio_code:*:*Range: >=0.7.0,<=0.20.2
Patches
Vulnerability mechanics
References
1- github.com/weaveworks/vscode-gitops-tools/security/advisories/GHSA-873x-829r-gxcpnvdThird Party Advisory
News mentions
0No linked articles in our index yet.