A vulnerability was identified in continuedev continue up to 1.2.22. This affects the function lsTool of the file core/tools/implementations/lsTool.ts of the component JSON-RPC Server. Such manipulation of the argument dirPath leads to path traversal. An attack has to be approached locally. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way.
References
| Link | Resource |
|---|---|
| https://gist.github.com/YLChen-007/da04e032993a4b2324df915f9ecf9831 | Exploit Third Party Advisory |
| https://vuldb.com/submit/811428 | Exploit Third Party Advisory VDB Entry |
| https://vuldb.com/vuln/364395 | Third Party Advisory VDB Entry |
| https://vuldb.com/vuln/364395/cti | Permissions Required VDB Entry |
| https://vuldb.com/submit/811428 | Exploit Third Party Advisory VDB Entry |
Configurations
History
19 May 2026, 17:30
| Type | Values Removed | Values Added |
|---|---|---|
| CPE | cpe:2.3:a:continue:continue:*:*:*:*:*:visual_studio_code:*:* |
19 May 2026, 14:32
| Type | Values Removed | Values Added |
|---|---|---|
| First Time |
Continue continue
Continue |
|
| CPE | cpe:2.3:a:continue:continue:*:*:*:*:*:*:*:* | |
| References | () https://gist.github.com/YLChen-007/da04e032993a4b2324df915f9ecf9831 - Exploit, Third Party Advisory | |
| References | () https://vuldb.com/submit/811428 - Exploit, Third Party Advisory, VDB Entry | |
| References | () https://vuldb.com/vuln/364395 - Third Party Advisory, VDB Entry | |
| References | () https://vuldb.com/vuln/364395/cti - Permissions Required, VDB Entry |
18 May 2026, 20:16
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://vuldb.com/submit/811428 - |
18 May 2026, 00:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-05-18 00:16
Updated : 2026-05-19 17:30
NVD link : CVE-2026-8770
Mitre link : CVE-2026-8770
CVE.ORG link : CVE-2026-8770
JSON object : View
Products Affected
continue
- continue
CWE
CWE-22
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
