
Proof-of-concept for CVE-2021-26700: remote code execution in the VSCode npm-script extension via malicious workspace settings.json, with detailed exploitation and remediation guidance.
Fixed 10th February 2021 in https://github.com/microsoft/vscode-npm-scripts/commit/cdd5e507564e0cc0f60bcccf184822be3fd73e07
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-26700
Remote code execution vulnerability in the eg2.vscode-npm-script
(Tested on version 0.3.13) VSCode extension means that a malicious .vscode/settings.json in a project can cause
remote code execution when a file named package.json is viewed.
This vulnerability did not fall under any active Microsoft bug bounty program, but was reported to and handled by MSRC.
Without a malicious .vscode/settings.json file in a repository, upon viewing a package.json file, with the
eg2.vscode-npm-script extension installed, the command will be executed.
npm ls --depth 0 --jsonBy setting the npm.bin key in a projects settings.json eg. to ./payload.sh, viewing the package.json will
instead execute ./payload.sh ls --depth 0 --json from the directory containing the package.json.
This vulnerability breaks the assumption that source-code can be safely read.
An example of how this could be used by an attacker is:
package.jsonpayload.sh is executedI've seen two ways of mitigating malicious VSCode Workspace settings.json
Forbid the settings to be set per workspace. This is already used by VSCode for git.path, terminal.integrated.shell.linux and a few other settings.
This could break compatibility for some users, but has precedent.
Reference: https://vscode.readthedocs.io/en/latest/getstarted/settings/#settings-and-security
If this setting is set in a workspace, prompt the user to confirm the setting before executing the binary.
This will not break existing compatibility, and is the route taken by the ESLint Extension as of version 2.1.7.
eg2.vscode-npm-scriptlinux-poc directory as a folder in VSCodepackage.json file to view it/tmp/output.txt will be created to demonstrate executioneg2.vscode-npm-scriptwindows-poc directory as a folder in VSCodepackage.json file to view itcalc.exe will be openedNote: I was unable to use a relative path for the binary in Windows, however this may be due to my lack of familiarity with Windows