VS Code flaw exposes GitHub OAuth tokens via one-click attack on GitHub.dev, enabling private repo access and token theft.
Two months after Rapid7 discovered the hole in the Git service, the project maintainer has yet to patch the bug.