execSync of the file vsix-publish.js. The manipulation leads to command injection.This vulnerability is uniquely identified as CVE-2026-25046. Local access is required to approach this attack. No exploit exists.
You should upgrade the affected component.
SOCIAL SHARE CARD GENERATOR