{"id":"CVE-2021-30502","details":"The unofficial vscode-ghc-simple (aka Simple Glasgow Haskell Compiler) extension before 0.2.3 for Visual Studio Code allows remote code execution via a crafted workspace configuration with replCommand.","modified":"2026-04-12T02:46:36.196157Z","published":"2021-04-25T03:15:07.203Z","references":[{"type":"ADVISORY","url":"https://github.com/dramforever/vscode-ghc-simple/blob/master/CHANGELOG.md#v023"},{"type":"ADVISORY","url":"https://github.com/dramforever/vscode-ghc-simple/releases"},{"type":"ADVISORY","url":"https://vuln.ryotak.me/advisories/38"},{"type":"FIX","url":"https://github.com/dramforever/vscode-ghc-simple/commit/bc7f6f0b857dade46ea51496d8bd1a4edef39b46"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/dramforever/vscode-ghc-simple","events":[{"introduced":"0"},{"fixed":"b883e7ba59a3daf3db22c58d8a85dd0648a4dc74"},{"fixed":"bc7f6f0b857dade46ea51496d8bd1a4edef39b46"}],"database_specific":{"extracted_events":[{"introduced":"0"},{"fixed":"0.2.3"}],"cpe":"cpe:2.3:a:simple_glasgow_haskell_compiler_project:simple_glasgow_haskell_compiler:*:*:*:*:*:visual_studio_code:*:*","source":["CPE_FIELD","REFERENCES"]}}],"versions":["v0.0.1","v0.0.10","v0.0.2","v0.0.3","v0.0.4","v0.0.5","v0.0.6","v0.0.7","v0.0.8","v0.1.0","v0.1.1","v0.1.10","v0.1.11","v0.1.12","v0.1.13","v0.1.14","v0.1.15","v0.1.16","v0.1.17","v0.1.18","v0.1.19","v0.1.2","v0.1.20","v0.1.22","v0.1.23","v0.1.24","v0.1.3","v0.1.4","v0.1.5","v0.1.6","v0.1.7","v0.1.8","v0.1.9","v0.2.0","v0.2.1","v0.2.2"],"database_specific":{"source":"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2021-30502.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"}]}