Gistpad is a VS Code extension that provides inline code snippet and note management, with a narrow vulnerability footprint centered on the core Gistpad product itself. The observed weakness class reflects authorization-control concerns in how the extension manages access to stored snippets and collaborative features, a characteristic surface for a tool handling user-created content and sharing workflows.
The number and severity of CVEs published that impact products developed by Gistpad Project over time
Signals from CVEs in this vendor scope (1 CVEs).
1 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-29642MEDIUM GistPad before 0.2.7 allows a crafted workspace folder to change the URL for the Gist API, which leads to leakage of GitHub access tokens. | Mar 30, 2021 | 5.3 | 20 | NO | NO |
Signals from CVEs in this vendor scope (1 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Gistpad Project.
Media articles that mention a CVE ID that affects a product developed by Gistpad Project — matched by CVE ID, not by vendor name.