CVE-2022-41034 is a critical remote code execution vulnerability in Visual Studio Code versions 1.4.0 through 1.71.1. The flaw allows attackers to craft malicious links or websites that, when accessed by a Visual Studio Code user, can execute arbitrary commands on the victim's machine and any connected remote systems via the Remote Development feature. The vulnerability exploits the trust model in VSCode, particularly with Jupyter Notebook files opened in trusted mode, enabling attackers to bypass security restrictions and run code in trusted mode. The exploit abuses the 'command:' URI handler and the 'workbench.action.terminal.new' command to launch terminals and execute arbitrary commands. Both web-based (vscode.dev, GitHub Codespaces, github.dev) and desktop versions are affected, though the impact is greater on web-based implementations.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository contains a single Metasploit module (vscode_ipynb_remote_dev_exec.rb) that exploits CVE-2022-41034, a remote code execution vulnerability in Microsoft VSCode (versions 1.4.0 to 1.71.1) when opening Jupyter notebook (.ipynb) files. The exploit abuses the trust model bypass, allowing a malicious .ipynb file to execute arbitrary code via embedded HTML/JavaScript that triggers the opening of a new terminal window in VSCode, which then runs attacker-controlled commands. The module sets up an HTTP server to deliver the crafted .ipynb file to the victim. It supports both Windows and Linux targets, with configurable payload options. The exploit is weaponized, providing a reverse shell or arbitrary command execution upon successful exploitation. The only file in the repository is the Metasploit module itself, written in Ruby.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.