Microsoft Visual Studio Code
12 known vulnerabilities in Microsoft Visual Studio Code, 1 critical, with patch priority, exploit likelihood and the news covering them.
Latest vulnerabilities
- CVE-2026-81383 CVSS 7.4 high Use of incorrectly-resolved name or reference in Visual Studio Code allows an unauthorized attacker to disclose information over a network.
- CVE-2026-81381 CVSS 7.5 high Insufficiently protected credentials in GitHub Copilot and Visual Studio Code allows an unauthorized attacker to disclose information over…
- CVE-2026-81380 CVSS 5.9 medium Improper neutralization of special elements used in a command ('command injection') in GitHub Copilot and Visual Studio Code allows an…
- CVE-2026-81379 CVSS 8.2 high Not failing securely ('failing open') in Visual Studio Code allows an unauthorized attacker to bypass a security feature over a network.
- CVE-2026-81378 CVSS 8.2 high Interpretation conflict in Visual Studio Code allows an unauthorized attacker to bypass a security feature over a network.
- CVE-2026-81377 CVSS 6.5 medium Improper limitation of a pathname to a restricted directory ('path traversal') in Visual Studio Code allows an unauthorized attacker to…
- CVE-2026-81376 CVSS 9.6 critical Incomplete comparison with missing factors in Visual Studio Code allows an unauthorized attacker to bypass a security feature over a…
- CVE-2026-81357 CVSS 8.2 high Server-side request forgery (ssrf) in Visual Studio Code allows an unauthorized attacker to bypass a security feature over a network.
- CVE-2026-81356 CVSS 8.2 high Inconsistent interpretation of http requests ('http request/response smuggling') in Visual Studio Code allows an unauthorized attacker to…
- CVE-2026-78462 CVSS 8.8 high Authorization bypass through user-controlled key in Visual Studio Code allows an unauthorized attacker to bypass a security feature over a…
- CVE-2026-78461 CVSS 7.4 high Improper limitation of a pathname to a restricted directory ('path traversal') in Visual Studio Code allows an unauthorized attacker to…
- CVE-2026-70334 CVSS 7.8 high Incomplete list of disallowed inputs in Visual Studio Code allows an unauthorized attacker to bypass a security feature locally.