CVE-2026-28353
Trivy Vulnerability Scanner is a VS Code extension that helps find vulnerabilities. In Trivy VSCode Extension version 1.8.12, which was distributed via OpenVSX marketplace was compromised and contained malicious code designed to leverage local AI coding agent to collect and exfiltrate sensitive information. Users using the affected artifact are advised to immediately remove it and rotate environment secrets. The malicious artifact has been removed from the marketplace. No other affected artifacts have been identified.
Scoring
- Severity
- CRITICAL
- CVSS base score
- 10
- CVSS vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
- EPSS probability
- 0.45%
- CWE
- CWE-506
- Published
- 2026-03-05
- Last modified
- 2026-03-12
Affected products
- aquasecurity trivy-vscode-extension
Weakness type
Related vulnerabilities
- CVE-2026-74232 — Zbtlink MQWrt yunmgrd Cloud C2 Implant
- CVE-2026-77651 — The arrayref crate 0.3.10 for Rust can trigger execution of malicious code when compiling a project...
- CVE-2026-77650 — The append-only-vec crate 0.1.9 for Rust can trigger execution of malicious code when compiling a...
- CVE-2026-77649 — The internment crate 0.8.7 for Rust can trigger execution of malicious code when compiling a...
- CVE-2026-73532 — Fluent Forms Pro 6.2.7 Embedded Malicious Code via Tampered Plugin Build
- CVE-2026-73533 — Ninja Tables Pro 5.2.11 Embedded Malicious Code via Tampered Plugin Build
- CVE-2026-48161 — react18-use was vulnerable to malicious code execution via compromised commits
- CVE-2026-48160 — react-tracked was vulnerable to malicious code execution via compromised commits