2024 Cognition Devin — CVE-2024-56083, VSCode live share
Data compromised
Code write access; potential system compromise
Technical writeup
Critical vulnerability: attackers could gain write access via VSCode live share URL during 'Use Devin's Machine' sessions. CVSS 8.1. Exposed by streamers; patched same day. Prompt injection also allows malware execution.
Root cause
Broken access control; prompt injection