Microsoft Visual Studio Code vulnerabilities
55 known vulnerabilities affecting microsoft/visual_studio_code.
Total CVEs
55
CISA KEV
0
Public exploits
1
Exploited in wild
0
Severity breakdown
CRITICAL2HIGH44MEDIUM8LOW1
Vulnerabilities
Page 1 of 3
CVE-2026-41613HIGHCVSS 8.8fixed in 1.119.1≥ 1.0.0, < 1.119.12026-05-12
CVE-2026-41613 [HIGH] CWE-78 CVE-2026-41613: Session fixation in Visual Studio Code allows an unauthorized attacker to elevate privileges over a
Session fixation in Visual Studio Code allows an unauthorized attacker to elevate privileges over a network.
nvd
CVE-2026-41109HIGHCVSS 8.8fixed in 1.119.1≥ 1.0.0, < 1.119.12026-05-12
CVE-2026-41109 [HIGH] CWE-74 CVE-2026-41109: Improper neutralization of special elements in output used by a downstream component ('injection') i
Improper neutralization of special elements in output used by a downstream component ('injection') in GitHub Copilot and Visual Studio allows an unauthorized attacker to bypass a security feature over a network.
nvd
CVE-2026-41610MEDIUMCVSS 5.0fixed in 1.119.1≥ 1.0.0, < 1.119.12026-05-12
CVE-2026-41610 [MEDIUM] CWE-59 CVE-2026-41610: Improper neutralization of input during web page generation ('cross-site scripting') in Visual Studi
Improper neutralization of input during web page generation ('cross-site scripting') in Visual Studio Code allows an unauthorized attacker to bypass a security feature locally.
nvd
CVE-2026-41611LOWCVSS 3.3fixed in 1.119.1≥ 1.0.0, < 1.119.12026-05-12
CVE-2026-41611 [LOW] CWE-77 CVE-2026-41611: Improper neutralization of script-related html tags in a web page (basic xss) in Visual Studio Code
Improper neutralization of script-related html tags in a web page (basic xss) in Visual Studio Code allows an unauthorized attacker to execute code locally.
nvd
CVE-2026-21518HIGHCVSS 8.8fixed in 1.109.2≥ 1.0.0, < 1.110.12026-02-10
CVE-2026-21518 [HIGH] CWE-77 CVE-2026-21518: Improper neutralization of special elements used in a command ('command injection') in GitHub Copilo
Improper neutralization of special elements used in a command ('command injection') in GitHub Copilot and Visual Studio Code allows an unauthorized attacker to bypass a security feature over a network.
nvd
CVE-2026-21523HIGHCVSS 8.0fixed in 1.109.2≥ 1.0.0, < 1.110.12026-02-10
CVE-2026-21523 [HIGH] CWE-367 CVE-2026-21523: Time-of-check time-of-use (toctou) race condition in GitHub Copilot and Visual Studio allows an auth
Time-of-check time-of-use (toctou) race condition in GitHub Copilot and Visual Studio allows an authorized attacker to execute code over a network.
nvd
CVE-2025-64660HIGHCVSS 8.0fixed in 1.106.2≥ 1.0.0, < 1.106.22025-11-20
CVE-2025-64660 [HIGH] CWE-284 CVE-2025-64660: Improper access control in GitHub Copilot and Visual Studio Code allows an authorized attacker to ex
Improper access control in GitHub Copilot and Visual Studio Code allows an authorized attacker to execute code over a network.
nvd
CVE-2025-62453MEDIUMCVSS 5.0fixed in 1.105.0≥ 1.0.0, < 1.105.02025-11-11
CVE-2025-62453 [MEDIUM] CWE-693 CVE-2025-62453: Improper validation of generative ai output in GitHub Copilot and Visual Studio Code allows an autho
Improper validation of generative ai output in GitHub Copilot and Visual Studio Code allows an authorized attacker to bypass a security feature locally.
nvd
CVE-2025-55319CRITICALCVSS 9.8fixed in 1.104.0≥ 1.0.0, < 1.104.02025-09-12
CVE-2025-55319 [CRITICAL] CWE-77 CVE-2025-55319: Ai command injection in Agentic AI and Visual Studio Code allows an unauthorized attacker to execute
Ai command injection in Agentic AI and Visual Studio Code allows an unauthorized attacker to execute code over a network.
nvd
CVE-2025-21264HIGHCVSS 7.1fixed in 1.100.1≥ 1.0.0, < 1.100.12025-05-13
CVE-2025-21264 [HIGH] CWE-552 CVE-2025-21264: Files or directories accessible to external parties in Visual Studio Code allows an unauthorized att
Files or directories accessible to external parties in Visual Studio Code allows an unauthorized attacker to bypass a security feature locally.
nvd
CVE-2025-32726MEDIUMCVSS 6.8fixed in 1.99.1≥ 1.0.0, < 1.99.12025-04-12
CVE-2025-32726 [MEDIUM] CWE-284 CVE-2025-32726: Improper access control in Visual Studio Code allows an authorized attacker to elevate privileges lo
Improper access control in Visual Studio Code allows an authorized attacker to elevate privileges locally.
nvd
CVE-2025-26631HIGHCVSS 7.3fixed in 1.98.0≥ 1.0.0, < 1.98.02025-03-11
CVE-2025-26631 [HIGH] CWE-427 CVE-2025-26631: Uncontrolled search path element in Visual Studio Code allows an authorized attacker to elevate priv
Uncontrolled search path element in Visual Studio Code allows an authorized attacker to elevate privileges locally.
nvd
CVE-2025-24039HIGHCVSS 7.3fixed in 1.97.1≥ 1.0.0, < 1.97.12025-02-11
CVE-2025-24039 [HIGH] CWE-427 CVE-2025-24039: Visual Studio Code Elevation of Privilege Vulnerability
Visual Studio Code Elevation of Privilege Vulnerability
nvd
CVE-2025-24042HIGHCVSS 7.3fixed in 1.97.12025-02-11
CVE-2025-24042 [HIGH] CWE-284 CVE-2025-24042: Visual Studio Code JS Debug Extension Elevation of Privilege Vulnerability
Visual Studio Code JS Debug Extension Elevation of Privilege Vulnerability
nvd
CVE-2024-43488CRITICALCVSS 9.8vN/A2024-10-08
CVE-2024-43488 [CRITICAL] CWE-306 CVE-2024-43488: Missing authentication for critical function in Visual Studio Code extension for Arduino allows an u
Missing authentication for critical function in Visual Studio Code extension for Arduino allows an unauthenticated attacker to perform remote code execution through network attack vector.
nvd
CVE-2024-43601HIGHCVSS 7.1fixed in 1.94.12024-10-08
CVE-2024-43601 [HIGH] CWE-77 CVE-2024-43601: Visual Studio Code for Linux Remote Code Execution Vulnerability
Visual Studio Code for Linux Remote Code Execution Vulnerability
nvd
CVE-2024-26165HIGHCVSS 8.8fixed in 1.87.2≥ 1.0.0, < 1.87.22024-03-12
CVE-2024-26165 [HIGH] CWE-256 CVE-2024-26165: Visual Studio Code Elevation of Privilege Vulnerability
Visual Studio Code Elevation of Privilege Vulnerability
nvd
CVE-2023-36742HIGHCVSS 7.8fixed in 1.82.1≥ 1.0.0, < 1.82.12023-09-12
CVE-2023-36742 [HIGH] CVE-2023-36742: Visual Studio Code Remote Code Execution Vulnerability
Visual Studio Code Remote Code Execution Vulnerability
nvd
CVE-2023-33144MEDIUMCVSS 6.6≥ 1.0.0, < 1.792023-06-13
CVE-2023-33144 [MEDIUM] CWE-23 Visual Studio Code Spoofing Vulnerability
Visual Studio Code Spoofing Vulnerability
Visual Studio Code Spoofing Vulnerability
cvelistv5
CVE-2023-29338MEDIUMCVSS 6.6≥ 1.0.0, < 1.78.12023-05-09
CVE-2023-29338 [MEDIUM] CWE-285 Visual Studio Code Spoofing Vulnerability
Visual Studio Code Spoofing Vulnerability
Visual Studio Code Spoofing Vulnerability
cvelistv5
1 / 3Next →