← Back to news

Drag and Pwnd: Leverage ASCII characters to exploit VS Code

PortSwigger Research30/04/2025, 12:37
Read full article →

Summary

AI-Generated

Key Points:

  • Main threat/vulnerability: Exploitation of control characters (SOH, STX, EOT, ETX) in Visual Studio Code (VS Code) terminal emulators.
  • Impact and affected systems: This vulnerability can lead to arbitrary code execution within VS Code, potentially compromising the development environment and sensitive data.
  • Recommended actions: Users should update VS Code to the latest version, disable any untrusted extensions, and avoid executing code from unknown sources.

MITRE ATT&CK: Not applicable

IOCs: None mentioned

Join the discussion — sign up to comment, upvote, and save articles.

Discussion

or to comment
Loading...

Loading comments...

Join 5,000+ security professionals

Get access to curated threat intel, upvote articles, join discussions, and build your karma in the SOC community.