CVE-2021-26700
Remote code execution in vscode-npm-script
EPSS 6.0%
Description
Visual Studio Code npm-script Extension Remote Code Execution Vulnerability
How to fix CVE-2021-26700
No fixed version has been published yet. Mitigate by removing the affected package or applying upstream guidance from the references below.
- npm/vscode-npm-script—no fix listed
Is CVE-2021-26700 being exploited?
Moderate — EPSS is 6.0%. Track this CVE but it's not at the top of the prioritisation list.
Affected packages (1)
- >= 0.0.0