Skip to content
Draft
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
114 changes: 114 additions & 0 deletions patches/backported-patches.json
Original file line number Diff line number Diff line change
Expand Up @@ -88,5 +88,119 @@
"patch_path": "N/A",
"link": "https://github.com/microsoft/vscode/commit/bc2d56c6f8da22a4bd31f741fcb034208770f158",
"note": "Notebook Restricted-Mode bypass via mermaid render. Upstream vulnerable file extensions/mermaid-markdown-features/preview-src/notebook/index.ts (the 'temp.innerHTML = result' sink and renderMermaidBlocksInElement) does not exist in this branch's shipped source. The only mermaid extension here, mermaid-chat-features, renders diagrams via escapeHtmlText() into a <pre> and uses textContent (chat-webview-src/mermaidWebview.ts) inside a sandboxed webview with strict nonce CSP - no innerHTML of untrusted content. The markdown-language-features notebook renderer already sanitizes untrusted HTML with DOMPurify. No equivalent vulnerable innerHTML/insertAdjacentHTML sink for untrusted render output exists."
},
{
"finding_id": "CVE-2026-70336",
"affected_versions": "< 1.132.1",
"patch_path": "patches/common/fix-block-privileged-url-payload.diff",
"link": "https://github.com/microsoft/vscode/commit/ef3ccf912287348aafd04dc6cc2c5619d6ccb70f"
},
{
"finding_id": "GHSA-fp6w-v29h-43rj",
"affected_versions": "< 1.132.1",
"patch_path": "patches/common/fix-block-privileged-url-payload.diff",
"link": "https://github.com/microsoft/vscode/commit/ef3ccf912287348aafd04dc6cc2c5619d6ccb70f"
},
{
"finding_id": "CVE-2026-69320",
"affected_versions": "< 1.132.1",
"patch_path": "patches/common/fix-block-privileged-url-payload.diff",
"link": "https://github.com/microsoft/vscode/commit/ef3ccf912287348aafd04dc6cc2c5619d6ccb70f"
},
{
"finding_id": "GHSA-h29r-p8vr-4vfm",
"affected_versions": "< 1.132.1",
"patch_path": "patches/common/fix-block-privileged-url-payload.diff",
"link": "https://github.com/microsoft/vscode/commit/ef3ccf912287348aafd04dc6cc2c5619d6ccb70f"
},
{
"finding_id": "CVE-2026-69278",
"affected_versions": "< 1.132.1",
"patch_path": "patches/common/fix-terminal-workspace-trust-bypass.diff",
"link": "https://github.com/microsoft/vscode/commit/3154a68fc151bcafe371f89d197412645e6a7616"
},
{
"finding_id": "GHSA-h9j4-x76r-fvj4",
"affected_versions": "< 1.132.1",
"patch_path": "patches/common/fix-terminal-workspace-trust-bypass.diff",
"link": "https://github.com/microsoft/vscode/commit/3154a68fc151bcafe371f89d197412645e6a7616"
},
{
"finding_id": "CVE-2026-58650",
"affected_versions": "< 1.132.1",
"patch_path": "patches/common/fix-network-filter-domain-validation.diff",
"link": "https://github.com/microsoft/vscode/commit/06a2bc84d0555f4c7ebd176809673e61fa49c6ff"
},
{
"finding_id": "GHSA-h6v9-3cqc-v234",
"affected_versions": "< 1.132.1",
"patch_path": "patches/common/fix-network-filter-domain-validation.diff",
"link": "https://github.com/microsoft/vscode/commit/06a2bc84d0555f4c7ebd176809673e61fa49c6ff"
},
{
"finding_id": "CVE-2026-47285",
"affected_versions": "< 1.132.1",
"patch_path": "patches/common/fix-buffer-copy-extensions.diff",
"link": "https://github.com/microsoft/vscode/commit/ae7a28076f3076a10bd07b49cf7ff730c1773e61"
},
{
"finding_id": "GHSA-vcpf-2mpp-vx3v",
"affected_versions": "< 1.132.1",
"patch_path": "patches/common/fix-buffer-copy-extensions.diff",
"link": "https://github.com/microsoft/vscode/commit/ae7a28076f3076a10bd07b49cf7ff730c1773e61"
},
{
"finding_id": "CVE-2026-65675",
"affected_versions": "< 1.132.1",
"patch_path": "N/A",
"link": "https://github.com/advisories/GHSA-3hjg-cwxj-qfc6",
"note": "Copilot Chat security feature bypass - Copilot not present in Code Editor"
},
{
"finding_id": "GHSA-3hjg-cwxj-qfc6",
"affected_versions": "< 1.132.1",
"patch_path": "N/A",
"link": "https://github.com/advisories/GHSA-3hjg-cwxj-qfc6",
"note": "Copilot Chat security feature bypass - Copilot not present in Code Editor"
},
{
"finding_id": "CVE-2026-70335",
"affected_versions": "< 1.132.1",
"patch_path": "N/A",
"link": "https://github.com/advisories/GHSA-w79w-rj9h-vg4f",
"note": "Copilot Custom Agent Hook RCE - Copilot not present in Code Editor"
},
{
"finding_id": "GHSA-w79w-rj9h-vg4f",
"affected_versions": "< 1.132.1",
"patch_path": "N/A",
"link": "https://github.com/advisories/GHSA-w79w-rj9h-vg4f",
"note": "Copilot Custom Agent Hook RCE - Copilot not present in Code Editor"
},
{
"finding_id": "CVE-2026-59113",
"affected_versions": "< 1.132.1",
"patch_path": "N/A",
"link": "https://github.com/advisories/GHSA-36qf-jgq9-4m6j",
"note": "Fetch Web Page OS protocol handler RCE - webContentExtractor is electron-main only, not present in Code Editor web/reh-web builds"
},
{
"finding_id": "GHSA-36qf-jgq9-4m6j",
"affected_versions": "< 1.132.1",
"patch_path": "N/A",
"link": "https://github.com/advisories/GHSA-36qf-jgq9-4m6j",
"note": "Fetch Web Page OS protocol handler RCE - webContentExtractor is electron-main only, not present in Code Editor web/reh-web builds"
},
{
"finding_id": "CVE-2026-69306",
"affected_versions": "< 1.132.1",
"patch_path": "patches/common/fix-network-filter-domain-validation.diff",
"link": "https://github.com/microsoft/vscode/commit/af3a976e194030a94f6bfb5aebc5e0f4d66f5e41"
},
{
"finding_id": "GHSA-6xp2-9cj3-f488",
"affected_versions": "< 1.132.1",
"patch_path": "patches/common/fix-network-filter-domain-validation.diff",
"link": "https://github.com/microsoft/vscode/commit/af3a976e194030a94f6bfb5aebc5e0f4d66f5e41"
}
]
109 changes: 109 additions & 0 deletions patches/common/fix-block-privileged-url-payload.diff
Original file line number Diff line number Diff line change
@@ -0,0 +1,109 @@
Block privileged URL payload options in server

Prevents environment variable injection via startParamsEnv by ensuring
VSCODE_* critical vars cannot be overridden, sanitizes resolverEnv before
use in terminal channel, removes dangerous env vars case-insensitively
across all platforms, and restricts extension dev payload options to
non-production builds only.

Remove when Code-OSS is updated to >= 1.132.1.

@backported: https://github.com/microsoft/vscode/commit/ef3ccf912287348aafd04dc6cc2c5619d6ccb70f
@finding-id: CVE-2026-70336 GHSA-fp6w-v29h-43rj CVE-2026-69320 GHSA-h29r-p8vr-4vfm
Index: b/src/vs/base/common/processes.ts
===================================================================
--- a/src/vs/base/common/processes.ts
+++ b/src/vs/base/common/processes.ts
@@ -3,7 +3,7 @@
* Licensed under the MIT License. See License.txt in the project root for license information.
*--------------------------------------------------------------------------------------------*/

-import { IProcessEnvironment, isLinux } from './platform.js';
+import { IProcessEnvironment } from './platform.js';

/**
* Options to be passed to the external program or shell.
@@ -136,13 +136,16 @@ export function removeDangerousEnvVariab
return;
}

- // Unset `DEBUG`, as an invalid value might lead to process crashes
- // See https://github.com/microsoft/vscode/issues/130072
- delete env['DEBUG'];
-
- if (isLinux) {
- // Unset `LD_PRELOAD`, as it might lead to process crashes
- // See https://github.com/microsoft/vscode/issues/134177
- delete env['LD_PRELOAD'];
+ const dangerousEnvVariables = new Set([
+ 'DEBUG',
+ 'NODE_OPTIONS',
+ 'VSCODE_NODE_OPTIONS',
+ 'LD_PRELOAD',
+ 'DYLD_INSERT_LIBRARIES'
+ ]);
+ for (const key of Object.keys(env)) {
+ if (dangerousEnvVariables.has(key.toUpperCase())) {
+ delete env[key];
+ }
}
}
Index: b/src/vs/server/node/extensionHostConnection.ts
===================================================================
--- a/src/vs/server/node/extensionHostConnection.ts
+++ b/src/vs/server/node/extensionHostConnection.ts
@@ -40,12 +40,10 @@ export async function buildUserEnvironme
const env: IProcessEnvironment = {
...processEnv,
...userShellEnv,
- ...{
- VSCODE_ESM_ENTRYPOINT: 'vs/workbench/api/node/extensionHostProcess',
- VSCODE_HANDLES_UNCAUGHT_ERRORS: 'true',
- VSCODE_NLS_CONFIG: JSON.stringify(nlsConfig)
- },
- ...startParamsEnv
+ ...startParamsEnv,
+ VSCODE_ESM_ENTRYPOINT: 'vs/workbench/api/node/extensionHostProcess',
+ VSCODE_HANDLES_UNCAUGHT_ERRORS: 'true',
+ VSCODE_NLS_CONFIG: JSON.stringify(nlsConfig)
};

const binFolder = environmentService.isBuilt ? join(environmentService.appRoot, 'bin') : join(environmentService.appRoot, 'resources', 'server', 'bin-dev');
Index: b/src/vs/server/node/remoteTerminalChannel.ts
===================================================================
--- a/src/vs/server/node/remoteTerminalChannel.ts
+++ b/src/vs/server/node/remoteTerminalChannel.ts
@@ -9,6 +9,7 @@ import { cloneAndChange } from '../../ba
import { Disposable } from '../../base/common/lifecycle.js';
import * as path from '../../base/common/path.js';
import * as platform from '../../base/common/platform.js';
+import { removeDangerousEnvVariables } from '../../base/common/processes.js';
import { URI } from '../../base/common/uri.js';
import { IURITransformer } from '../../base/common/uriIpc.js';
import { IServerChannel } from '../../base/parts/ipc/common/ipc.js';
@@ -210,7 +211,9 @@ export class RemoteTerminalChannel exten
};


- const baseEnv = await buildUserEnvironment(args.resolverEnv, !!args.shellLaunchConfig.useShellEnvironment, platform.language, this._environmentService, this._logService, this._configurationService);
+ const resolverEnv = { ...args.resolverEnv };
+ removeDangerousEnvVariables(resolverEnv);
+ const baseEnv = await buildUserEnvironment(resolverEnv, !!args.shellLaunchConfig.useShellEnvironment, platform.language, this._environmentService, this._logService, this._configurationService);
this._logService.trace('baseEnv', baseEnv);

const reviveWorkspaceFolder = (workspaceData: IWorkspaceFolderData): IWorkspaceFolder => {
Index: b/src/vs/workbench/services/environment/browser/environmentService.ts
===================================================================
--- a/src/vs/workbench/services/environment/browser/environmentService.ts
+++ b/src/vs/workbench/services/environment/browser/environmentService.ts
@@ -302,8 +302,8 @@ export class BrowserWorkbenchEnvironment
extensionDevelopmentKind: undefined
};

- // Fill in selected extra environmental properties
- if (this.payload) {
+ // Extension host development options from the payload are only valid in development builds.
+ if (this.payload && !this.isBuilt) {
for (const [key, value] of this.payload) {
switch (key) {
case 'extensionDevelopmentPath':
47 changes: 47 additions & 0 deletions patches/common/fix-buffer-copy-extensions.diff
Original file line number Diff line number Diff line change
@@ -0,0 +1,47 @@
Always return copies of buffers to extensions

Returns a copied slice of the buffer in extHostCommands instead of
the original backing ArrayBuffer, preventing extensions from mutating
shared memory. Also simplifies webview stream chunk handling to use
VSBuffer.buffer which already returns a safe Uint8Array copy.

Remove when Code-OSS is updated to >= 1.132.1.

@backported: https://github.com/microsoft/vscode/commit/ae7a28076f3076a10bd07b49cf7ff730c1773e61
@finding-id: CVE-2026-47285 GHSA-vcpf-2mpp-vx3v
Index: b/src/vs/workbench/api/common/extHostCommands.ts
===================================================================
--- a/src/vs/workbench/api/common/extHostCommands.ts
+++ b/src/vs/workbench/api/common/extHostCommands.ts
@@ -101,7 +101,8 @@ export class ExtHostCommands implements
return extHostTypeConverter.location.to(obj);
}
if (obj instanceof VSBuffer) {
- return obj.buffer.buffer;
+ // Create a copy of the buffer since the original buffer is owned by the extension host and might be reused for other commands
+ return obj.buffer.buffer.slice(obj.buffer.byteOffset, obj.buffer.byteOffset + obj.buffer.byteLength);
}
if (!Array.isArray(obj)) {
return obj;
Index: b/src/vs/workbench/contrib/webview/browser/webviewElement.ts
===================================================================
--- a/src/vs/workbench/contrib/webview/browser/webviewElement.ts
+++ b/src/vs/workbench/contrib/webview/browser/webviewElement.ts
@@ -820,7 +820,7 @@ export class WebviewElement extends Disp
onData: (chunk) => {
if (!closed) {
try {
- controller.enqueue(new Uint8Array<ArrayBuffer>(chunk.buffer.buffer as ArrayBuffer, chunk.buffer.byteOffset, chunk.buffer.byteLength));
+ controller?.enqueue(new Uint8Array(chunk.buffer));
} catch {
closed = true;
this._activeStreamControllers.delete(controller);
@@ -861,7 +861,7 @@ export class WebviewElement extends Disp
});
listenStream(result.stream, {
onData: (chunk) => {
- const data = new Uint8Array(chunk.buffer.buffer, chunk.buffer.byteOffset, chunk.buffer.byteLength);
+ const data = new Uint8Array(chunk.buffer);
this._send('did-load-resource-chunk', { id, data }, [data.buffer]);
},
onError: () => {
Loading