Skip to content
RCE Vulnerabilities Exploited in GitHub Codespaces via VS Code Config Files

RCE Vulnerabilities Exploited in GitHub Codespaces via VS Code Config Files

First seen 6 Feb 2026, 00:21 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster March 12, 2026 at 13:27 UTC

Orca Security researchers identified multiple attack vectors in GitHub Codespaces that allow remote code execution (RCE) by opening malicious repositories or pull requests. Attackers can exploit VS Code configuration files to execute arbitrary commands, exfiltrate GitHub tokens, and access sensitive resources without user consent. This affects developers using the cloud-based development environment.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 192d ago How this analysis works

More articles in this cluster (2)