CNNVD-202602-1408 Information

CNNVD ID

CNNVD-202602-1408

CVE-2026-25931

  • CNNVD Published: 2026-02-09

Description (Chinese)

Spelling Checker for Visual Studio Code是Street Side Software开源的一个简单的源代码拼写检查器。 Spelling Checker for Visual Studio Code v4.5.4之前版本存在安全漏洞,该漏洞源于配置信任标志处理不当,可能导致不受信任的工作空间执行攻击者控制的Node.js代码。

Description (English)

Spelling Checker for Vital Studio Code is a simple source spell checker for Street Side Software open source. There was a security loophole in the pre-version of Spelling Checker for Trust Studio Code v4.5.4, which stemmed from the mishandling of the configuration of the trust sign, which could lead to Node.js code not controlled by trusted strikers.

Vulnerability Type

其他

Affected Vendor

Street Side Software

Published

2026-02-09

Last Modified

2026-02-24

References

https://drive.google.com/file/d/1mT4SOkkHSHU6NFfKwekysydAd3FUAC6K/view?usp=sharing https://github.com/streetsidesoftware/vscode-spell-checker/commit/f39af9a3a6f2a939a57171a24161ed735d41c575 https://github.com/streetsidesoftware/vscode-spell-checker/releases/tag/code-spell-checker-v4.5.4 https://github.com/streetsidesoftware/vscode-spell-checker/security/advisories/GHSA-mggq-68mr-58vj

Patch

https://github.com/streetsidesoftware/vscode-spell-checker/releases

Share on: