www.securityweek.com 6/4/2026, 8:20:50 AM · external

VS Code flaw exposes GitHub tokens via malicious Jupyter notebook

VS Code flaw exposes GitHub tokens via malicious Jupyter notebook
CyberSIXT Evidence Panel
Primary Source blog.ammaraskar.com

A severe vulnerability has been disclosed in Visual Studio Code (VS Code) that allows attackers to steal a user's GitHub token, potentially granting access to their repositories. The vulnerability, found by researcher Ammar Askar, is exploitative through a crafted Jupyter notebook that, when opened in a web version of VS Code, can install a malicious extension to harvest tokens. A fix was released by Microsoft soon after disclosure.

This incident follows a trend where researchers publicly disclose vulnerabilities after poor experiences with prior reporting, raising concerns over responsible disclosure practices and security research.

View Primary Source Via www.securityweek.com

Article by CyberSIXT