VDB
GCVE-110-OSM-2026-10424
GCVE-110-OSM-2026-10424
Advisory PublishedCVSS 5.4/10
Suspicious package detected.
Microsoft removal context:
Extension ID: codebuddy-znt.codebuddy-znt
Publisher: codebuddy-znt
Removal Date: 8/7/2026
Violation Type: untrustworthy
Removed from the VS Code Marketplace by Microsoft for violating marketplace policies.
Source: https://github.com/microsoft/vsmarketplace/blob/main/RemovedPackages.md
GitHub exposure: 7 public file(s) on GitHub reference this extension (e.g. .vscode/extensions.json recommendations, devcontainer configs, or docs). These repositories may be distributing or recommending the removed extension:
- mthcht/awesome-lists: Lists/VSCODE Extensions/feeds/ioc_all_extension_ids.txt
- microsoft/vsmarketplace: RemovedPackages.md
- vsxsentry/vsxsentry.github.io: feeds/ioc_all_extension_ids.txt
- vsxsentry/vsxsentry.github.io: feeds/vsxsentry_opencti_import.csv
- vsxsentry/vsxsentry.github.io: feeds/vsxsentry_misp_warninglist.json
- vsxsentry/vsxsentry.github.io: feeds/vsxsentry_sentinel_watchlist.csv
- kalachkar/vsmex: metadata/msft_vscode_flagged_extensions.csv
Weaknesses (CWE)
CWE-506Embedded Malicious Code
Risk Scores
CVSS 3.1
5.4/10
Medium · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N
Affected Products
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| unknown | codebuddy-znt.codebuddy-znt | all (affected) | — |
Browse GCVE Records
3,530 records in the GCVE database · Updated September 5, 2026
No matching records found.
Explore Further
Investigate this vulnerability in the interactive console or download the raw GCVE record.