ThreatCluster

GitHub Token Theft Vulnerability Exploited via github.dev

First seen 3 Jun 2026, 07:24 UTC News.Ycombinatorblog.ammaraskar.comen.wikipedia.org 94% similarity 63

Article Content

Browse articles
ThreatCluster

A vulnerability has been identified that allows attackers to steal GitHub OAuth tokens by exploiting the github.dev feature. This feature enables users to access a lightweight version of VSCode in their browser, which can interact with GitHub repositories. The OAuth token is not limited to a specific repository, granting full access to all repositories the user can access. Attackers can leverage bugs in the VSCode webviews to exfiltrate these tokens. The attack vector relies on the ability to execute JavaScript within the webviews, which are designed to isolate content for security. This vulnerability poses a significant risk to users with access to private repositories. As of now, no patches or fixes have been reported. Users are advised to be cautious when using the github.dev feature.

Key Points: • Attackers can steal GitHub OAuth tokens via the github.dev feature. • The vulnerability allows full access to all repositories linked to the stolen token. • No patches or fixes have been reported as of now.

ThreatCluster AI

Timeline

2026-06-02
Vulnerability reported
A vulnerability allowing GitHub token theft via github.dev was reported, affecting users with access to private repositories.
News.Ycombinator
2026-06-03
Blog post details attack method
A blog post elaborated on how attackers can exploit the vulnerability using VSCode's webviews to exfiltrate OAuth tokens.
blog.ammaraskar.com

Community

Browse all →

Tracked Entities in This Story