AWS Toolkit for Visual Studio Code: Credential Cache Vulnerability Requires Update
AWS Toolkit for Visual Studio Code versions below 4.10.0 have a security flaw where CodeCatalyst bearer tokens are cached with world-readable permissions and not deleted after sessions end. Local attackers could steal these tokens to gain unauthorized access. If you're using this extension, upgrade to version 4.10.0 or later immediately—this one's worth your attention.
source: [aws/security-bulletin]