Impact
The Ruby LSP VS Code extension allowed a malicious repository to supply a .vscode/settings.json file that could override the path to the Ruby executable, the version manager executables, or the Bundler Gemfile at startup. By setting these values to attacker‑controlled targets, opening and trusting the repository would execute arbitrary code under the developer’s account. The vulnerability is limited to the VS Code extension; the Ruby LSP gem and clients in other editors are not affected.
Affected Systems
The affected product is Shopify’s Ruby LSP VS Code extension. Versions prior to 0.10.4 are impacted. Users who have installed or are operating those older versions of the extension are at risk.
Risk and Exploitability
The CVSS score of 5.4 indicates moderate severity. No EPSS score is available, and the vulnerability is not listed in the CISA KEV catalog. Exploitation requires a malicious repository containing crafted workspace settings; the attacker must get the developer to open and trust the repository, after which code runs with the developer’s privileges. The risk is therefore moderate to high if trusted, but the likelihood of exploitation in the wild appears limited.
OpenCVE Enrichment