cbcvebase.
CVE-2025-26631
published 2025-03-11

CVE-2025-26631: Uncontrolled search path element in Visual Studio Code allows an authorized attacker to elevate privileges locally.

high7.3CVSS 3.1
AVLACLPRLUIRSUCHIHAH
Uncontrolled search path element in Visual Studio Code allows an authorized attacker to elevate privileges locally.

Affected

3 ranges
VendorProductVersion rangeFixed in
microsoftvisual_studio_code< 1.98.01.98.0
microsoftvisual_studio_code>= 1.0.0 < 1.98.01.98.0
msrcvisual_studio_code