CVE-2026-28353

Trivy Vulnerability Scanner is a VS Code extension that helps find vulnerabilities. In Trivy VSCode Extension version 1.8.12, which was distributed via OpenVSX marketplace was compromised and contained malicious code designed to leverage local AI coding agent to collect and exfiltrate sensitive information. Users using the affected artifact are advised to immediately remove it and rotate environment secrets. The malicious artifact has been removed from the marketplace. No other affected artifacts have been identified.
CVSS

No CVSS.

Configurations

No configuration.

History

No history.

Information

Published : 2026-03-05 20:16

Updated : 2026-03-09 13:36


NVD link : CVE-2026-28353

Mitre link : CVE-2026-28353

CVE.ORG link : CVE-2026-28353


JSON object : View

Products Affected

No product.

CWE
CWE-506

Embedded Malicious Code