Malicious Code in Trivy Vulnerability Scanner Extension for VS Code by Aqua Security
CVE-2026-28353

10CRITICAL

Key Information:

Vendor
CVE Published:
5 March 2026

What is CVE-2026-28353?

The Trivy VS Code Extension version 1.8.12 was compromised, containing malicious code that exploited a local AI coding agent to collect and exfiltrate sensitive information. Users who installed the affected version are strongly advised to remove it immediately and rotate any compromised environment secrets. The dangerous extension has since been removed from the OpenVSX marketplace, with no additional affected artifacts reported at this time.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

trivy-vscode-extension = 1.8.12

References

CVSS V4

Score:
10
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.