CVE-2025-55319

CWE-77Command Injection4 documents4 sources
Severity
9.8CRITICAL
EPSS
0.1%
top 75.94%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedSep 12

Description

Ai command injection in Agentic AI and Visual Studio Code allows an unauthorized attacker to execute code over a network.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HExploitability: 2.8 | Impact: 5.9

Affected Packages2 packages

CVEListV5microsoft/visual_studio_code1.0.01.104.0

🔴Vulnerability Details

2
CVEList
Agentic AI and Visual Studio Code Remote Code Execution Vulnerability2025-09-12
GHSA
GHSA-gv2h-mcrv-w23w: Ai command injection in Agentic AI and Visual Studio Code allows an unauthorized attacker to execute code over a network2025-09-12

📋Vendor Advisories

1
Microsoft
Agentic AI and Visual Studio Code Remote Code Execution Vulnerability2025-09-09