Vulnerabilities
One Click in VS Code Steals Your GitHub Token — the Researcher Skipped Coordinated Disclosure
Researcher Ammar Askar disclosed a one-click attack via VS Code's GitHub.dev that steals a GitHub OAuth token with read-write access to private repos. He published the PoC with about an hour's notice, blaming Microsoft's disclosure process.