> Markdown version of [/videos/717-you-click-you-lose-a-practical-look-at-vscode-s-security?t=3](https://www.wearedevelopers.com/videos/717-you-click-you-lose-a-practical-look-at-vscode-s-security?t=3). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # You click, you lose: a practical look at VSCode's security Think opening a workspace in VS Code is safe? Attackers can exploit its web-based architecture to execute arbitrary code the moment you click a malicious repository link. - **Speakers:** Thomas Chauchefoin, Paul Gerste - **Event:** World Congress 2023 - **Published:** September 27, 2023 - **Duration:** 29:47 - **URL:** https://www.wearedevelopers.com/videos/717-you-click-you-lose-a-practical-look-at-vscode-s-security ## Summary Code editors like VS Code are prime targets for threat actors because they inherently grant access to proprietary source code, credentials, and production environments. While developers often assume that simply opening a file or workspace is safe, the underlying architecture of modern IDEs creates complex attack surfaces. Built on the Electron framework, VS Code relies on a multi-process model that bridges privileged Node.js backends with sandboxed Chromium renderers, blurring the line between web vulnerabilities and desktop exploits. This architecture introduces several critical attack vectors. Deep OS integration features, such as custom protocol handlers, can be exploited via argument injection; for example, manipulating the built-in Git extension's clone URL to execute arbitrary commands. Similarly, vulnerable third-party extensions might inadvertently expose local network services or introduce cross-site scripting (XSS). Because the IDE's UI is largely rendered via HTML and Markdown, attackers can use XSS in markdown previews or web views to escape unprivileged contexts, abuse internal message passing, and achieve remote code execution. To mitigate these threats, Microsoft introduced the Workspace Trust model, which requires developers to explicitly authorize execution contexts before interacting with a project. However, systemic risks persist outside these boundaries. Core utilities often execute before trust is established, meaning a malicious repository with a crafted `.git/config` can trigger remote code execution the moment a folder is opened in the IDE or navigated via the terminal. Ultimately, the overlapping security contexts of web technologies and desktop privileges dictate that developers must treat untrusted code repositories with the same caution as unverified executables. **Keywords:** vs code security, electron architecture, remote code execution, cross-site scripting, ide attack surfaces, malicious git configurations, argument injection vulnerabilities, workspace trust model, protocol handler exploits, node integration risks, developer threat modeling, extension sandbox escapes, local network service exposures, supply chain threats ## Chapters 1. **Introduction to VS Code security risks and threat models** (00:03) — The growing threat of targeting developers and the security trade-offs of deep IDE integrations. 1. **VS Code architecture and security process separation boundaries** (04:57) — How VS Code isolates processes using Electron, webviews, and message passing to maintain security boundaries. 1. **Exploiting exposed network services in developer IDE extensions** (10:27) — How extensions that expose local web servers and debuggers introduce critical network vulnerabilities. 1. **Injecting malicious arguments via OS URI protocol handlers** (12:42) — Bypassing operating system handlers to inject malicious arguments into background execution binaries like git. 1. **Exploiting malicious workspace settings and local git configurations** (17:17) — How workspace configurations and local git hooks can execute commands before explicit trust is granted. 1. **Executing cross-site scripting in web views and Markdown** (23:01) — Weaponizing Markdown preview components and post messages to bypass same-origin policies and trigger internal commands. 1. **Reporting IDE vulnerabilities and bug bounty program takeaways** (26:47) — Analyzing bug bounty program realities for desktop applications and why IDE security boundaries remain opaque. ## Related Moments - [Risks of malicious VS Code extensions and AI assistants](https://www.wearedevelopers.com/videos/1794-wearedevelopers-live-from-javascript-to-webassembly-high-performance-charting-and-more) (from "WeAreDevelopers LIVE – From JavaScript to WebAssembly, High-Performance Charting and More") - [Visual Studio Code as a target for exploitation](https://www.wearedevelopers.com/videos/283-vulnerable-vs-code-extensions-are-now-at-your-front-door) (from "Vulnerable VS Code extensions are now at your front door") - [Identifying security risks in developer IDE environments](https://www.wearedevelopers.com/videos/468-securing-your-application-software-supply-chain) (from "Securing your application software supply-chain") - [Addressing remote code execution vulnerabilities in text editors](https://www.wearedevelopers.com/videos/1803-wearedevelopers-live-keeping-up-with-styles-data-more) (from "WeAreDevelopers LIVE – Keeping Up with Styles, Data & More") - [Exploiting path traversal vulnerabilities in code editor extensions](https://www.wearedevelopers.com/videos/716-hack-proof-the-node-js-runtime-the-mechanics-and-defense-of-path-traversal-attacks) (from "Hack-Proof The Node.js runtime: The Mechanics and Defense of Path Traversal Attacks") - [Mitigating extension vulnerabilities and applying workspace trust](https://www.wearedevelopers.com/videos/283-vulnerable-vs-code-extensions-are-now-at-your-front-door) (from "Vulnerable VS Code extensions are now at your front door") ## Related Articles - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [Dev Digest 176: Expensive Agents, Taking Over VSCode and Safer Vibe Coding](https://www.wearedevelopers.com/magazine/603-dev-digest-176-expensive-agents-taking-over-vscode-and-safer-vibe-coding) - [Dev Digest 138 - Are you secure about this?](https://www.wearedevelopers.com/magazine/486-dev-digest-138-are-you-secure-about-this) - [Dev Digest 131 - AI'm not sure about OSS](https://www.wearedevelopers.com/magazine/472-dev-digest-131-ai-m-not-sure-about-oss) ## Related Jobs - [Staff Developer Advocate, GitHub Security Lab](https://www.wearedevelopers.com/jobs/ext/2628442-staff-developer-advocate-github-security-lab) at **GitHub** - [Senior Software Engineer, Sandboxes (Eu Or East Coast Preferred)](https://www.wearedevelopers.com/jobs/ext/2145616-senior-software-engineer-sandboxes-eu-or-east-coast-preferred) at **Docker, Inc.** - [SoC Offensive Security Staff Engineer](https://www.wearedevelopers.com/jobs/48479-soc-offensive-security-staff-engineer) at **Arm** - [Senior Software Engineer, Sandboxes (Eu Or East Coast Preferred)](https://www.wearedevelopers.com/jobs/ext/2159298-senior-software-engineer-sandboxes-eu-or-east-coast-preferred) at **Docker, Inc.** - [Senior Software Engineer, Sandboxes (Eu Or East Coast Preferred)](https://www.wearedevelopers.com/jobs/ext/2145730-senior-software-engineer-sandboxes-eu-or-east-coast-preferred) at **Docker, Inc.** - [Senior Software Engineer, Sandboxes (Eu Or East Coast Preferred)](https://www.wearedevelopers.com/jobs/ext/2161904-senior-software-engineer-sandboxes-eu-or-east-coast-preferred) at **Docker, Inc.**