Post #3075962
2026-01-22 10:03 UTC
@morl99@hessen.social yes, I agree it could be more explicit. That'd also aid with the step of attackers trying to obfuscate the code execution by adding whitespace in the json.
Replies (1)
-
@dermoth@jasette.facil.services 2026-01-26 01:59
@mushu@social.troll.academy @morl99@hessen.social The problem is that it could give a false sense security. I'm not super familiar with vscode but I bet there are dozens ways of exploiting this, many of which are yet to be known. Blocking it all at once is the safe thing to do.