subasraj / flashpost-support

Flashpost is a lightweight Rest API Client Extension for Visual Studio Code.
MIT License
12 stars 0 forks source link

Security Issue #60

Open mserajnik opened 1 week ago

mserajnik commented 1 week ago

There is a security issue in this extension; I won't go into further details here but I strongly recommend not to use it for the time being.

I couldn't find a way to privately contact the extension developer (@subasraj) and VS Marketplace support decided not to act when I told them about it and instead referred me to this repository (even after telling them there is no apparent way to contact the developer in private).

@subasraj: contact me via email (see my GitHub profile) and provide proof that the email you are using is yours (e.g., by adding it to your GitHub profile or adding a note to this repository) and I will provide the details.

maximejobin commented 22 hours ago

That issue is as responsible as it gets. You went above and beyond.