cbcvebase.

Microsoft Visual Studio Code vulnerabilities

87 known vulnerabilities affecting microsoft/visual_studio_code.

Total CVEs
87
CISA KEV
0
Public exploits
1
Exploited in wild
0
Severity breakdown
CRITICAL4HIGH65MEDIUM17LOW1

Vulnerabilities

Page 2 of 5
CVE-2026-81356P3HIGHCVSS 8.2fixed in 1.136.2≥ 1.0.0, < 1.136.22026-09-08
CVE-2026-81356 [HIGH] CWE-444 CVE-2026-81356: Inconsistent interpretation of http requests ('http request/response smuggling') in Visual Studio Co Inconsistent interpretation of http requests ('http request/response smuggling') in Visual Studio Code allows an unauthorized attacker to bypass a security feature over a network.
nvd
CVE-2026-81378P3HIGHCVSS 8.2fixed in 1.136.2≥ 1.0.0, < 1.136.22026-09-08
CVE-2026-81378 [HIGH] CWE-436 CVE-2026-81378: Interpretation conflict in Visual Studio Code allows an unauthorized attacker to bypass a security f Interpretation conflict in Visual Studio Code allows an unauthorized attacker to bypass a security feature over a network.
nvd
CVE-2022-21991P3HIGHCVSS 8.1≥ 1.0.0, < 1.64.12022-02-09
CVE-2022-21991 [HIGH] CVE-2022-21991: Visual Studio Code Remote Development Extension Remote Code Execution Vulnerability Visual Studio Code Remote Development Extension Remote Code Execution Vulnerability
nvd
CVE-2020-1416P3HIGHCVSS 8.8fixed in 1.47.1vunspecified2020-07-14
CVE-2020-1416 [HIGH] CWE-269 CVE-2020-1416: An elevation of privilege vulnerability exists in Visual Studio and Visual Studio Code when they loa An elevation of privilege vulnerability exists in Visual Studio and Visual Studio Code when they load software dependencies, aka 'Visual Studio and Visual Studio Code Elevation of Privilege Vulnerability'.
nvd
CVE-2026-81379P3HIGHCVSS 8.2fixed in 1.136.2≥ 1.0.0, < 1.136.22026-09-08
CVE-2026-81379 [HIGH] CWE-636 CVE-2026-81379: Not failing securely ('failing open') in Visual Studio Code allows an unauthorized attacker to bypas Not failing securely ('failing open') in Visual Studio Code allows an unauthorized attacker to bypass a security feature over a network.
nvd
CVE-2026-69306P3HIGHCVSS 8.2fixed in 1.132.1≥ 1.0.0, < 1.132.12026-08-11
CVE-2026-69306 [HIGH] CWE-636 CVE-2026-69306: Not failing securely ('failing open') in Visual Studio Code allows an unauthorized attacker to bypas Not failing securely ('failing open') in Visual Studio Code allows an unauthorized attacker to bypass a security feature over a network.
nvd
CVE-2021-43891P3HIGHCVSS 7.8fixed in 1.63.2≥ 1.0.0, < 1.63.12021-12-15
CVE-2021-43891 [HIGH] CVE-2021-43891: Visual Studio Code Remote Code Execution Vulnerability Visual Studio Code Remote Code Execution Vulnerability
nvd
CVE-2025-64660P3HIGHCVSS 8.0fixed in 1.106.2≥ 1.0.0, < 1.106.22025-11-20
CVE-2025-64660 [HIGH] CWE-284 CVE-2025-64660: Improper access control in GitHub Copilot and Visual Studio Code allows an authorized attacker to ex Improper access control in GitHub Copilot and Visual Studio Code allows an authorized attacker to execute code over a network.
nvd
CVE-2026-81381P3HIGHCVSS 7.5fixed in 1.136.2≥ 1.0.0, < 1.136.22026-09-08
CVE-2026-81381 [HIGH] CWE-522 CVE-2026-81381: Insufficiently protected credentials in GitHub Copilot and Visual Studio Code allows an unauthorized Insufficiently protected credentials in GitHub Copilot and Visual Studio Code allows an unauthorized attacker to disclose information over a network.
nvd
CVE-2026-45482P3HIGHCVSS 8.4fixed in 1.123.22026-06-09
CVE-2026-45482 [HIGH] CWE-22 CVE-2026-45482: Improper limitation of a pathname to a restricted directory ('path traversal') in GitHub Copilot and Improper limitation of a pathname to a restricted directory ('path traversal') in GitHub Copilot and Visual Studio Code allows an unauthorized attacker to bypass a security feature locally.
nvd
CVE-2026-81357P3HIGHCVSS 8.2fixed in 1.136.2≥ 1.0.0, < 1.136.22026-09-08
CVE-2026-81357 [HIGH] CWE-918 CVE-2026-81357: Server-side request forgery (ssrf) in Visual Studio Code allows an unauthorized attacker to bypass a Server-side request forgery (ssrf) in Visual Studio Code allows an unauthorized attacker to bypass a security feature over a network.
nvd
CVE-2026-70335P3HIGHCVSS 7.8fixed in 1.132.1≥ 1.0.0, < 1.132.12026-08-11
CVE-2026-70335 [HIGH] CWE-78 CVE-2026-70335: Improper neutralization of special elements used in an os command ('os command injection') in GitHub Improper neutralization of special elements used in an os command ('os command injection') in GitHub Copilot and Visual Studio Code allows an unauthorized attacker to elevate privileges locally.
nvd
CVE-2026-58650P3HIGHCVSS 7.8fixed in 1.132.1≥ 1.0.0, < 1.132.12026-08-11
CVE-2026-58650 [HIGH] CWE-639 CVE-2026-58650: Authorization bypass through user-controlled key in Visual Studio Code allows an unauthorized attack Authorization bypass through user-controlled key in Visual Studio Code allows an unauthorized attacker to bypass a security feature locally.
nvd
CVE-2026-69278P3HIGHCVSS 7.8fixed in 1.132.1≥ 1.0.0, < 1.132.12026-08-11
CVE-2026-69278 [HIGH] CWE-693 CVE-2026-69278: Incorrect authorization in Visual Studio Code allows an unauthorized attacker to bypass a security f Incorrect authorization in Visual Studio Code allows an unauthorized attacker to bypass a security feature locally.
nvd
CVE-2026-78461P3HIGHCVSS 7.4fixed in 1.136.2≥ 1.0.0, < 1.136.22026-09-08
CVE-2026-78461 [HIGH] CWE-22 CVE-2026-78461: Improper limitation of a pathname to a restricted directory ('path traversal') in Visual Studio Code Improper limitation of a pathname to a restricted directory ('path traversal') in Visual Studio Code allows an unauthorized attacker to bypass a security feature over a network.
nvd
CVE-2020-16881P3HIGHCVSS 7.8fixed in 1.48.1≥ 1.0.0, < publication2020-09-11
CVE-2020-16881 [HIGH] CVE-2020-16881: <p>A remote code execution vulnerability exists in Visual Studio Code when a user is tricked into op A remote code execution vulnerability exists in Visual Studio Code when a user is tricked into opening a malicious 'package.json' file. An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the current user. If the current user is logged on with administrative user rights, an attacker could take control of the aff
nvd
CVE-2020-17023P3HIGHCVSS 7.8≥ 1.0.0, < publication2020-10-16
CVE-2020-17023 [HIGH] CVE-2020-17023: <p>A remote code execution vulnerability exists in Visual Studio Code when a user is tricked into op A remote code execution vulnerability exists in Visual Studio Code when a user is tricked into opening a malicious 'package.json' file. An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the current user. If the current user is logged on with administrative user rights, an attacker could take control of the aff
nvd
CVE-2026-47292P3HIGHCVSS 7.8≥ 1.0.0, < 1.123.12026-06-09
CVE-2026-47292 [HIGH] CWE-94 CVE-2026-47292: Inclusion of functionality from untrusted control sphere in Visual Studio Code allows an unauthorize Inclusion of functionality from untrusted control sphere in Visual Studio Code allows an unauthorized attacker to elevate privileges locally.
nvd
CVE-2026-81383P3HIGHCVSS 7.4fixed in 1.136.2≥ 1.0.0, < 1.136.22026-09-08
CVE-2026-81383 [HIGH] CWE-706 CVE-2026-81383: Use of incorrectly-resolved name or reference in Visual Studio Code allows an unauthorized attacker Use of incorrectly-resolved name or reference in Visual Studio Code allows an unauthorized attacker to disclose information over a network.
nvd
CVE-2020-1192P3HIGHCVSS 7.8≥ 1.0.0, < publication2020-05-21
CVE-2020-1192 [HIGH] CVE-2020-1192: A remote code execution vulnerability exists in Visual Studio Code when the Python extension loads w A remote code execution vulnerability exists in Visual Studio Code when the Python extension loads workspace settings from a notebook file. An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the current user. If the current user is logged on with administrative user rights, an attacker could take control of the a
nvd
Microsoft Visual Studio Code vulnerabilities | cvebase