Attackers can abuse VS Code configuration files for RCE when a GitHub Codespaces user opens a repository or pull request.
The classic VS Code is great and all, but these specialized forks are better for certain programming tasks ...