CVE-2026-28353 | Teknoloji dünyasından en güncel haberleri ve güvenlikle ilgili gelişmeleri takip edin.

Trivy Vulnerability Scanner is a VS Code extension that helps find vulnerabilities. In Trivy VSCode Extension version 1.8.12, which was distributed via OpenVSX…
Critical CVSS: 10.0

CVE-2026-28353

Trivy Vulnerability Scanner is a VS Code extension that helps find vulnerabilities. In Trivy VSCode Extension version 1.8.12, which was distributed via OpenVSX marketplace was compromised and contained malicious code designed to leverage local AI coding agent to collect and exfiltrate sensitive information. Users using the affected artifact are advised to immediately remove it and rotate environment secrets. The malicious artifact has been removed from the marketplace. No other affected artifacts have been identified.
Vendor
-
Product
-
CWE
CWE-506
Yayın Tarihi
2026-03-05 20:16:16
Güncelleme
2026-03-09 13:36:08
Source Identifier
security-advisories@github.com
KEV Date Added
-

Kategoriler

Referanslar