{"slug": "i-gave-my-vs-code-extension-to-a-cybersecurity-model-and-it-found-an-infinite", "title": "I Gave My VS Code Extension to a Cybersecurity Model and It Found an Infinite Hang", "summary": "A developer audited CertView, their own published VS Code certificate-inspection extension, using OpenAI's Daybreak Blue defensive cyber model and found two denial-of-service flaws that can freeze the editor with a file under 256 KiB. One is an O(n²) PEM parser that re-joins accumulated lines on every read; the other passes an attacker-controlled PKCS#12 iteration count straight to node-forge, where a 128-byte 0xFF integer parses to Infinity and makes the key-derivation loop non-terminating, triggered automatically by the extension's empty-password attempt on file open. Both issues were fixed before publication, and the same audit run against GPT-5.6-Sol found the freeze but not the Infinity case or a size-check race window.", "body_md": "CertView is a VS Code extension I wrote to inspect certificates: you open a `.pem`, a `.p12`, a `.cer`, and it shows you the subject, the dates, the fingerprint, all offline. It's published on the Marketplace. It parses binary files that anyone can send you, so it's attack surface, and until this week I'd never looked at it thinking like an attacker.\n\nI now have access to Daybreak Blue, OpenAI's defensive cyber model lane. I gave it my own code, the one I maintain, and asked it one concrete thing: assume I send you a malicious certificate and Juan opens it in the editor, what breaks? It found two ways to hang VS Code with a file smaller than a phone photo. I fixed both before writing this.\n\nThe PEM parser splits the file into blocks. For every line it read, it re-joined the entire accumulated block to measure its size. One `join` per line. That's O(n²): double the lines, quadruple the work.\n\nI measured it on the actual code. A PEM block with many single-character lines, staying under the 256 KiB limit the plugin itself enforces:\n\nThe size limit didn't help, because it was checked *after* re-joining all the lines. The fix is a one-line idea: keep a length counter and do a single `join` when closing the block. O(n) instead of O(n²).\n\nThis one is worse, and it's the mess that made me stop.\n\nA `.p12` file carries a number inside: how many iterations to use to derive the key from the password. It's a legitimate mechanism — more iterations, more expensive to brute-force. The problem is that CertView passed that number straight to the parsing library (`node-forge`) exactly as it came from the file, with no cap, and the derivation runs synchronously: while it runs, VS Code doesn't respond.\n\nAn attacker can declare a huge number. And here's the detail that turns it into a hang instead of a delay: `node-forge` reads that number with `parseInt`. A 128-byte integer of `0xFF` inside the file converts, in JavaScript, into `Infinity`. The derivation loop is `for (round = 0; round < iterations; round++)`. With `iterations = Infinity`, it's not that it takes a long time: it never ends.\n\nI verified it in one line of Node:\n\n```\nparseInt(\"f\".repeat(256), 16) === Infinity // true\n```\n\nAnd the worst part: CertView automatically tries the empty password as soon as you open the file, before asking you anything. So the attacker doesn't need to know any password. You open the `.p12` to see what it is, and the editor freezes on you forever.\n\nThe fix is a preflight: before touching the library, CertView now reads the iteration numbers directly from the file structure — no `parseInt`, so there's no path to `Infinity` — and rejects anything above 100,000. If the file asks for more, it doesn't get parsed.\n\nNot everything was a finding. The model reviewed the webview (the view where certificate data is shown) and confirmed that hostile fields are properly escaped, that the Content-Security-Policy is restrictive, that passwords aren't logged or saved, and that encrypted private keys aren't even decrypted. Instead of inventing vulnerabilities to pad out a list, it said where the code was already fine. That's what makes it useful: a report that's pure findings doesn't let you know what it checked and ruled out.\n\nI ran the same audit, with the exact same request word for word, on two models: GPT-5.6-Sol (the general-purpose one) and Daybreak Blue (the defensive one). Both read the code, neither invented anything. The difference wasn't that Blue \"did something forbidden\": it was depth. Sol saw that the PKCS#12 \"freezes the host\"; Blue also saw the `Infinity` case, which is the difference between slow and non-terminating. And Blue found one more thing Sol didn't: a race window between measuring the file size and reading it.\n\nThat's the honest part of the experiment. This was defensive work on my own code, and for that the general-purpose model also does the job. The specialized lane showed up in the detail, not in unlocking something the other refused to do.\n\nTwo things I didn't expect, and I'm mentioning them because they're the part that doesn't make it into the announcement:\n\nTo get the account enabled I had to verify identity and set a physical YubiKey as the sole login — one single key, the one that now opens all my work. It's not optional, and it makes sense: a model with the brakes taken off for security work is exactly what someone would want to use with a stolen account.\n\nAnd on the day I ran the audit, what slowed me down most wasn't either model: it was the tool's sandbox, which stopped being able to isolate the network on that machine and blocked all file reads. The model was ready; the plumbing around it wasn't. It's almost always like that.\n\nUpdate to 0.5.1. Both vulnerabilities are fixed there, with tests that fail if either comes back. And if you're writing a parser for something sent to you from outside: measure your limits *before* doing the expensive work, not after, and never pass a library a number that came from the file without a cap.", "url": "https://wpnews.pro/news/i-gave-my-vs-code-extension-to-a-cybersecurity-model-and-it-found-an-infinite", "canonical_source": "https://dev.to/jtorchia/i-gave-my-vs-code-extension-to-a-cybersecurity-model-and-it-found-an-infinite-hang-5e03", "published_at": "2026-10-08 01:01:59+00:00", "updated_at": "2026-10-08 01:17:00.543769+00:00", "lang": "en", "topics": ["ai-tools", "ai-products", "artificial-intelligence"], "entities": ["CertView", "VS Code", "OpenAI", "Daybreak Blue", "GPT-5.6-Sol", "node-forge"], "also_reported_by": [], "alternates": {"html": "https://wpnews.pro/news/i-gave-my-vs-code-extension-to-a-cybersecurity-model-and-it-found-an-infinite", "markdown": "https://wpnews.pro/news/i-gave-my-vs-code-extension-to-a-cybersecurity-model-and-it-found-an-infinite.md", "text": "https://wpnews.pro/news/i-gave-my-vs-code-extension-to-a-cybersecurity-model-and-it-found-an-infinite.txt", "jsonld": "https://wpnews.pro/news/i-gave-my-vs-code-extension-to-a-cybersecurity-model-and-it-found-an-infinite.jsonld"}}