{"rewrite":{"id":"r_2888a8f893f6745520e3b290","clusterId":"c_c7eb5235e53afa044da2e285","slug":"github-dev-vulnerability-lets-attackers-steal-tokens-with-one-click","model":"deepseek-v4-flash","headline":"Github.Dev Vulnerability Lets Attackers Steal Tokens With One Click","summary":"A security researcher has disclosed a vulnerability in GitHub's browser-based development environment github.dev that allows an attacker to steal a user's GitHub authentication token by tricking them into clicking a single link. The bug exploits a mechanism in VS Code's Webview feature to execute an attacker-prepared extension.","whyItMatters":"The vulnerability turns a convenience feature of github.dev into a one-click token theft vector, putting private repositories at risk for any user who clicks a crafted link.","webCardHtml":"\u003cp\u003eSecurity researcher Ammar Askar has reported a vulnerability in github.dev, GitHub's browser-based development environment. The bug allows an attacker to steal a user's GitHub OAuth token with a single click on a crafted link. The attack exploits a mechanism in VS Code's Webview feature that relays keyboard operations from isolated display areas to the editor's main body. Scripts running inside a Webview can send programmatically generated key operations, faking shortcut sequences that install an attacker-prepared extension. Once the extension runs, it can access the GitHub API token used by github.dev and query private repositories. Askar's proof of concept displays the stolen token and private repository list in an info box; a real attack could send that data to an attacker's server.\u003c/p\u003e","blueskyPost":"The github.dev bug exploits VS Code's Webview to run an attacker-controlled extension. The attack vector is a single link, not a multi-step exploit.","twitterPost":"The github.dev bug uses VS Code's Webview to execute an attacker extension. One click is the only requirement.","threadsPost":"The github.dev vulnerability uses VS Code's Webview to load an attacker-prepared extension. The attack requires one click on a link. No multi-step chain, no user interaction beyond that single click.","newsletterBlurb":"A security researcher has disclosed a vulnerability in github.dev that lets attackers steal GitHub authentication tokens with a single click. The bug exploits VS Code's Webview keyboard relay mechanism to install a malicious extension that can access private repositories.","attributionJson":"[{\"source\":\"GIGAZINE\",\"url\":\"https://gigazine.net/news/20260604-github-token-stealing/\",\"title\":\"GitHub access token can be stolen with just one click on a link, vulnerability reported\"}]","lintFlagsJson":null,"lintHits":0,"costUsd":0,"inputTokens":4152,"outputTokens":526,"status":"published","repairAttempts":0,"nextRepairAt":null,"factsAttemptedAt":1780570343,"createdAt":"2026-06-04T10:42:38.000Z","publishedAt":"2026-06-04T10:46:19.000Z","updatedAt":"2026-06-04T10:46:19.000Z"},"cluster":{"id":"c_c7eb5235e53afa044da2e285","canonicalTitle":"GitHubのアクセストークンが「リンクを1回クリックしただけ」で盗まれる脆弱性が報告される","representativeArticleId":"a_58b98658e1e3ccad69e01618","sourceCount":1,"writtenSourceCount":1,"writeAttempts":0,"isSolo":true,"entitiesJson":"{\"anime_titles\":[],\"manga_titles\":[],\"work_titles\":[],\"studios\":[],\"people\":[],\"type\":\"news\",\"domain\":\"other\",\"is_roundup\":false}","contentType":"news","status":"published","firstSeenAt":"2026-06-04T10:05:00.000Z","lastSeenAt":"2026-06-04T10:05:00.000Z","updatedAt":"2026-06-04T10:46:20.000Z"},"attribution":[{"source":"GIGAZINE","url":"https://gigazine.net/news/20260604-github-token-stealing/","title":"GitHubのアクセストークンが「リンクを1回クリックしただけ」で盗まれる脆弱性が報告される"}],"entities":{"anime_titles":[],"manga_titles":[],"work_titles":[],"studios":[],"people":[],"type":"news","domain":"other","is_roundup":false},"keyFacts":["Security researcher Ammar Askar disclosed a vulnerability in github.dev, GitHub's browser-based development environment.","The bug lets an attacker steal a user's GitHub OAuth token with a single click on a crafted link.","The attack exploits VS Code's Webview feature to send fake keyboard shortcuts that install an attacker-prepared extension.","Once installed, the extension can access the GitHub API token used by github.dev and query private repositories.","Askar's proof of concept displays the stolen token and private repository list; a real attack could send that data to an attacker's server."]}
