CVE Explorer
CVE-2026-25931
vscode-spell-checker is a basic spell checker that works well with code and documents. Prior to v4.5.4, DocumentSettings._determineIsTrusted treats the configuration value cSpell.trustedWorkspace as the authoritative trust flag. The value defaults to true (package.json) and is read from workspace configuration each time settings are fetched. The code coerces any truthy value to true and forwards it to ConfigLoader.setIsTrusted , which in turn allows JavaScript/TypeScript configuration files ( .c
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
1
Preserved source conflicts
No provider value was silently selected as the winner.
cwe · 3 assertions
{"cweId":"CWE-807","description":"CWE-807: Reliance on Untrusted Inputs in a Security Decision","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:f96232daf357f1a5211561941bf3f37ec090dda56442000ede023b6f483ee6ce · sha256:dcd0de1a4c13f193… · /containers/cna/problemTypes/1/descriptions/0
{"cweId":"CWE-276","description":"CWE-276: Incorrect Default Permissions","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:f96232daf357f1a5211561941bf3f37ec090dda56442000ede023b6f483ee6ce · sha256:dcd0de1a4c13f193… · /containers/cna/problemTypes/0/descriptions/0
{"cweId":"CWE-829","description":"CWE-829: Inclusion of Functionality from Untrusted Control Sphere","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:f96232daf357f1a5211561941bf3f37ec090dda56442000ede023b6f483ee6ce · sha256:dcd0de1a4c13f193… · /containers/cna/problemTypes/2/descriptions/0
Affected products and versions
1 source assertion{"product":"vscode-spell-checker","vendor":"streetsidesoftware","versions":[{"status":"affected","version":"< 4.5.4"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:f96232daf357f1a5211561941bf3f37ec090dda56442000ede023b6f483ee6ce · sha256:dcd0de1a4c13f193… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"attackComplexity":"LOW","attackVector":"LOCAL","availabilityImpact":"HIGH","baseScore":7.8,"baseSeverity":"HIGH","confidentialityImpact":"HIGH","integrityImpact":"HIGH","privilegesRequired":"NONE","scope":"UNCHANGED","userInteraction":"REQUIRED","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","version":"3.1"},"metric_type":"cvssV3_1"}
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:f96232daf357f1a5211561941bf3f37ec090dda56442000ede023b6f483ee6ce · sha256:dcd0de1a4c13f193… · /containers/cna/metrics/0/cvssV3_1
CWE assertions
3 source assertions{"cweId":"CWE-807","description":"CWE-807: Reliance on Untrusted Inputs in a Security Decision","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:f96232daf357f1a5211561941bf3f37ec090dda56442000ede023b6f483ee6ce · sha256:dcd0de1a4c13f193… · /containers/cna/problemTypes/1/descriptions/0
{"cweId":"CWE-276","description":"CWE-276: Incorrect Default Permissions","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:f96232daf357f1a5211561941bf3f37ec090dda56442000ede023b6f483ee6ce · sha256:dcd0de1a4c13f193… · /containers/cna/problemTypes/0/descriptions/0
{"cweId":"CWE-829","description":"CWE-829: Inclusion of Functionality from Untrusted Control Sphere","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:f96232daf357f1a5211561941bf3f37ec090dda56442000ede023b6f483ee6ce · sha256:dcd0de1a4c13f193… · /containers/cna/problemTypes/2/descriptions/0
Source references
4 source assertions{"name":"https://drive.google.com/file/d/1mT4SOkkHSHU6NFfKwekysydAd3FUAC6K/view?usp=sharing","tags":["x_refsource_MISC"],"url":"https://drive.google.com/file/d/1mT4SOkkHSHU6NFfKwekysydAd3FUAC6K/view?usp=sharing"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:f96232daf357f1a5211561941bf3f37ec090dda56442000ede023b6f483ee6ce · sha256:dcd0de1a4c13f193… · /containers/cna/references/2
{"name":"https://github.com/streetsidesoftware/vscode-spell-checker/commit/f39af9a3a6f2a939a57171a24161ed735d41c575","tags":["x_refsource_MISC"],"url":"https://github.com/streetsidesoftware/vscode-spell-checker/commit/f39af9a3a6f2a939a57171a24161ed735d41c575"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:f96232daf357f1a5211561941bf3f37ec090dda56442000ede023b6f483ee6ce · sha256:dcd0de1a4c13f193… · /containers/cna/references/1
{"name":"https://github.com/streetsidesoftware/vscode-spell-checker/releases/tag/code-spell-checker-v4.5.4","tags":["x_refsource_MISC"],"url":"https://github.com/streetsidesoftware/vscode-spell-checker/releases/tag/code-spell-checker-v4.5.4"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:f96232daf357f1a5211561941bf3f37ec090dda56442000ede023b6f483ee6ce · sha256:dcd0de1a4c13f193… · /containers/cna/references/3
{"name":"https://github.com/streetsidesoftware/vscode-spell-checker/security/advisories/GHSA-mggq-68mr-58vj","tags":["x_refsource_CONFIRM"],"url":"https://github.com/streetsidesoftware/vscode-spell-checker/security/advisories/GHSA-mggq-68mr-58vj"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:f96232daf357f1a5211561941bf3f37ec090dda56442000ede023b6f483ee6ce · sha256:dcd0de1a4c13f193… · /containers/cna/references/0
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.