A security researcher discovered a vulnerability in GitHub's browser-based VSCode editor (github.dev) where an OAuth token with full repository access is passed from github.com to github.dev. A threat actor could exploit this via a malicious Jupyter notebook extension that bypasses publisher trust checks, stealing the token and gaining read/write access to all of a developer's private repositories. Microsoft applied a stopgap fix. The disclosure also sparked debate about responsible disclosure ethics after the researcher gave only one hour of notice — citing a prior bad experience where Microsoft fixed his reported bug but gave him no credit. The incident highlights the power imbalance between vendors and security researchers, and the lack of consistent standards around coordinated vulnerability disclosure.