Attackers can abuse VS Code configuration files for RCE when a GitHub Codespaces user opens a repository or pull request.
In February 2026, U.S. Rep. Thomas Massie, R-Ky., said he had a flash drive with the "complete list of files belonging to ...