Vulnerability in Blackbox VS Code Extension
Technical Vulnerability Disclosure: Blackbox VS Code Extension Author: Frank Sx Date: 21/01/2025 Subject: Technical Disclosure of Vulnerability in Blackbox VS Code Extension Overview This post serves as a formal technical disclosure of a critical security vulnerability identified in the Blackbox VS Code extension (Blackboxapp.blackboxagent) up to the latest version. The vulnerability involves self-referral exploits that could enable unauthorized users to generate and redeem referral IDs, leading to potential abuse of the referral system. Vulnerability Details Description The vulnerability is rooted in the implementation of the referral ID generation and redemption processes within the Blackbox API, specifically located at: https://file+.vscode-resource.vscode-cdn.net/home/xxxxx/.vscode-oss/extensions/blackboxapp.blackboxagent-2.8.12/webview-ui/build/static/js/main.js Identified Issues: Self-Referral Exploit: The current implementation allows any user to generate a r...