Microsoft Visual Studio Code vulnerabilities
87 known vulnerabilities affecting microsoft/visual_studio_code.
Total CVEs
87
CISA KEV
0
Public exploits
1
Exploited in wild
0
Severity breakdown
CRITICAL4HIGH65MEDIUM17LOW1
Vulnerabilities
Page 1 of 5
CVE-2022-41034P2HIGHCVSS 7.8PoCfixed in 1.72.1≥ 1.0.0, < 1.72.12022-10-11
CVE-2022-41034 [HIGH] CVE-2022-41034: Visual Studio Code Remote Code Execution Vulnerability
Visual Studio Code Remote Code Execution Vulnerability
nvd
CVE-2022-30129P2HIGHCVSS 8.8fixed in 1.67.1≥ 1.0.0, < 1.67.12022-05-10
CVE-2022-30129 [HIGH] CVE-2022-30129: Visual Studio Code Remote Code Execution Vulnerability
Visual Studio Code Remote Code Execution Vulnerability
nvd
CVE-2024-43488P2CRITICALCVSS 9.8v-2024-10-08
CVE-2024-43488 [CRITICAL] CWE-306 CVE-2024-43488: Missing authentication for critical function in Visual Studio Code extension for Arduino allows an u
Missing authentication for critical function in Visual Studio Code extension for Arduino allows an unauthenticated attacker to perform remote code execution through network attack vector.
nvd
CVE-2025-55319P2CRITICALCVSS 9.8fixed in 1.104.0≥ 1.0.0, < 1.104.02025-09-12
CVE-2025-55319 [CRITICAL] CWE-77 CVE-2025-55319: Ai command injection in Agentic AI and Visual Studio Code allows an unauthorized attacker to execute
Ai command injection in Agentic AI and Visual Studio Code allows an unauthorized attacker to execute code over a network.
nvd
CVE-2026-69320P2HIGHCVSS 8.8fixed in 1.132.1≥ 1.0.0, < 1.132.12026-08-11
CVE-2026-69320 [HIGH] CWE-78 CVE-2026-69320: Improper neutralization of special elements used in an os command ('os command injection') in Visual
Improper neutralization of special elements used in an os command ('os command injection') in Visual Studio Code allows an unauthorized attacker to execute code over a network.
nvd
CVE-2026-70336P2HIGHCVSS 8.8fixed in 1.132.1≥ 1.0.0, < 1.132.12026-08-11
CVE-2026-70336 [HIGH] CWE-94 CVE-2026-70336: Improper control of generation of code ('code injection') in Visual Studio Code allows an unauthoriz
Improper control of generation of code ('code injection') in Visual Studio Code allows an unauthorized attacker to execute code over a network.
nvd
CVE-2026-81376P2CRITICALCVSS 9.6fixed in 1.136.2≥ 1.0.0, < 1.136.22026-09-08
CVE-2026-81376 [CRITICAL] CWE-693 CVE-2026-81376: Incomplete comparison with missing factors in Visual Studio Code allows an unauthorized attacker to
Incomplete comparison with missing factors in Visual Studio Code allows an unauthorized attacker to bypass a security feature over a network.
nvd
CVE-2026-47281P2CRITICALCVSS 9.6≥ 1.0.0, < 1.123.1≥ 1.0.0, < 1.123.22026-06-09
CVE-2026-47281 [CRITICAL] CWE-306 CVE-2026-47281: Missing authorization in Visual Studio Code allows an unauthorized attacker to elevate privileges ov
Missing authorization in Visual Studio Code allows an unauthorized attacker to elevate privileges over a network.
nvd
CVE-2026-21518P2HIGHCVSS 8.8fixed in 1.109.2≥ 1.0.0, < 1.110.12026-02-10
CVE-2026-21518 [HIGH] CWE-77 CVE-2026-21518: Improper neutralization of special elements used in a command ('command injection') in GitHub Copilo
Improper neutralization of special elements used in a command ('command injection') in GitHub Copilot and Visual Studio Code allows an unauthorized attacker to bypass a security feature over a network.
nvd
CVE-2026-78462P3HIGHCVSS 8.8fixed in 1.136.2≥ 1.0.0, < 1.136.22026-09-08
CVE-2026-78462 [HIGH] CWE-639 CVE-2026-78462: Authorization bypass through user-controlled key in Visual Studio Code allows an unauthorized attack
Authorization bypass through user-controlled key in Visual Studio Code allows an unauthorized attacker to bypass a security feature over a network.
nvd
CVE-2026-59113P3HIGHCVSS 8.8fixed in 1.132.1≥ 1.0.0, < 1.132.12026-08-11
CVE-2026-59113 [HIGH] CWE-862 CVE-2026-59113: Missing authorization in Visual Studio Code allows an unauthorized attacker to execute code over a n
Missing authorization in Visual Studio Code allows an unauthorized attacker to execute code over a network.
nvd
CVE-2026-41613P3HIGHCVSS 8.8fixed in 1.119.1≥ 1.0.0, < 1.119.12026-05-12
CVE-2026-41613 [HIGH] CWE-78 CVE-2026-41613: Session fixation in Visual Studio Code allows an unauthorized attacker to elevate privileges over a
Session fixation in Visual Studio Code allows an unauthorized attacker to elevate privileges over a network.
nvd
CVE-2020-0604P3HIGHCVSS 8.8fixed in 0.24.0≥ 1.0.0, < publication2020-08-17
CVE-2020-0604 [HIGH] CVE-2020-0604: A remote code execution vulnerability exists in Visual Studio Code when it process environment varia
A remote code execution vulnerability exists in Visual Studio Code when it process environment variables after opening a project. An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the current user. If the current user is logged on with administrative user rights, an attacker could take control of the affected sy
nvd
CVE-2019-0728P3HIGHCVSS 7.8vunspecified2019-03-05
CVE-2019-0728 [HIGH] CVE-2019-0728: A remote code execution vulnerability exists in Visual Studio Code when it process environment varia
A remote code execution vulnerability exists in Visual Studio Code when it process environment variables after opening a project, aka 'Visual Studio Code Remote Code Execution Vulnerability'.
nvd
CVE-2026-41109P3HIGHCVSS 8.8fixed in 1.119.1≥ 1.0.0, < 1.128.12026-05-12
CVE-2026-41109 [HIGH] CWE-74 CVE-2026-41109: Improper neutralization of special elements in output used by a downstream component ('injection') i
Improper neutralization of special elements in output used by a downstream component ('injection') in GitHub Copilot and Visual Studio allows an unauthorized attacker to bypass a security feature over a network.
nvd
CVE-2026-40376P3HIGHCVSS 8.1≥ 1.0.0, < 1.123.22026-06-09
CVE-2026-40376 [HIGH] CWE-20 CVE-2026-40376: Improper input validation in Visual Studio Code allows an unauthorized attacker to elevate privilege
Improper input validation in Visual Studio Code allows an unauthorized attacker to elevate privileges over a network.
nvd
CVE-2026-57102P3HIGHCVSS 8.8≥ 1.0.0, < 1.128.12026-07-14
CVE-2026-57102 [HIGH] CWE-200 CVE-2026-57102: Inclusion of functionality from untrusted control sphere in Visual Studio Code allows an unauthorize
Inclusion of functionality from untrusted control sphere in Visual Studio Code allows an unauthorized attacker to bypass a security feature over a network.
nvd
CVE-2024-26165P3HIGHCVSS 8.8fixed in 1.87.2≥ 1.0.0, < 1.87.22024-03-12
CVE-2024-26165 [HIGH] CWE-256 CVE-2024-26165: Visual Studio Code Elevation of Privilege Vulnerability
Visual Studio Code Elevation of Privilege Vulnerability
nvd
CVE-2026-50520P3HIGHCVSS 8.4≥ 1.0.0, < 1.128.12026-07-14
CVE-2026-50520 [HIGH] CWE-77 CVE-2026-50520: Improper neutralization of special elements used in a command ('command injection') in Visual Studio
Improper neutralization of special elements used in a command ('command injection') in Visual Studio Code allows an unauthorized attacker to execute code locally.
nvd
CVE-2026-21523P3HIGHCVSS 8.0fixed in 1.109.2≥ 1.0.0, < 1.110.12026-02-10
CVE-2026-21523 [HIGH] CWE-367 CVE-2026-21523: Time-of-check time-of-use (toctou) race condition in GitHub Copilot and Visual Studio allows an auth
Time-of-check time-of-use (toctou) race condition in GitHub Copilot and Visual Studio allows an authorized attacker to execute code over a network.
nvd
1 / 5Next →