CVE-2023-21779 (https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2023-21779): Visual Studio Code Remote Code Execution. With some digging, we can find some more information despite Microsoft's useless CVE: https://code.visualstudio.com/updates/v1_74 https://github.com/microsoft/vscode/issues/170992 https://github.com/microsoft/vscode/security/advisories/GHSA-p996-wrgh-crrj So, the fix is in 1.74.3, and the commit is (not associated with any tag according to Github..): https://github.com/microsoft/vscode/commit/5b8361bc717608db4359c2572d5b447f94bc3fb8 So, please bump to 1.74.3.
Bumped both to 1.74.3 and cleaned up all old versions
Thanks, all done!