www.securityweek.com 6/4/2026, 8:20:50 AM · external

VS Code flaw exposes GitHub tokens via malicious Jupyter notebook

VS Code flaw exposes GitHub tokens via malicious Jupyter notebook
CyberSIXT Evidence Panel
Primary Source blog.ammaraskar.com

A severe vulnerability has been disclosed in Visual Studio Code (VS Code) that allows attackers to steal a user's GitHub token, potentially granting access to their repositories. The vulnerability, found by researcher Ammar Askar, is exploitative through a crafted Jupyter notebook that, when opened in a web version of VS Code, can install a malicious extension to harvest tokens. A fix was released by Microsoft soon after disclosure.

This incident follows a trend where researchers publicly disclose vulnerabilities after poor experiences with prior reporting, raising concerns over responsible disclosure practices and security research.

View Primary Source Via www.securityweek.com

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline