localResourceRoots
should accept only URIs with the file
scheme
#135361
Labels
bug
Issue identified by VS Code Team member as probable bug
insiders-released
Patch has been released in VS Code Insiders
verified
Verification succeeded
webview
Webview issues
Milestone
Version: 1.62.0-insider (Universal)
Commit: 729d816
Date: 2021-10-18T05:21:54.840Z
Electron: 13.5.1
Chrome: 91.0.4472.164
Node.js: 14.16.0
V8: 9.1.269.39-electron.0
OS: Darwin arm64 20.6.0
Misconfigured
localResourceRoots
leads to a serious issue. And, we can easily misconfigure it.localResourceRoots
should accept only URIs with thefile
scheme.Steps to Reproduce:
asWebviewUri(this._extensionUri)
tolocalResourceRoots
, instead ofthis._extensionUri
. It is a misconfiguration.fetch
inside the WebView View can access to/etc/bashrc
.CC: @mjbvz
The text was updated successfully, but these errors were encountered: