1-Click GitHub Token Stealing via a VSCode Bug | Hacker News
TL;DR AI
2 min readKey summary
A writeup warns that the browser-based VS Code editor on github.dev may expose a signed-in GitHub session to token theft if a bug is present.
Because the editor is tied to a broad GitHub web login, stolen credentials could grant access far beyond a single repository.
The post argues for temporary, repo-scoped permissions instead of relying on a full GitHub session in a browser IDE.
The concern underscores how browser-based coding tools can widen the blast radius of any security vulnerability.
