CVE-2026-70334
massLocal security-feature bypass in Microsoft Visual Studio Code
CVE-2026-70334 is an incomplete list of disallowed inputs (CWE-184) in Microsoft Visual Studio Code, meaning the editor fails to block certain inputs and an attacker can thereby circumvent one of its built-in security features. Per the CVSS vector (AV:L/AC:L/PR:N/UI:R), exploitation requires local access plus user interaction: an unauthorized local attacker would need a user to open or act on crafted content in VS Code, after which the unfiltered input bypasses the security check. A successful bypass carries high impact on confidentiality, integrity, and availability of the local system (CVSS 3.1 score of 7.8 High), though the available description does not specify which security feature is affected. Anyone running Visual Studio Code is potentially affected; no affected or fixed version numbers were included in the source data. There is currently no known exploitation: no public proof-of-concept exists, the flaw is not in CISA's KEV catalog, and EPSS puts the 30-day exploitation probability at just 0.4%.
What to do: Update Visual Studio Code to the latest release from Microsoft, which addresses the incomplete input blocklist; since the flaw requires user interaction, exercise caution when opening files, folders, or workspaces from untrusted local sources. Because the attack is local, standard endpoint hygiene (limiting local attacker access) limits practical exposure.
| Microsoft Visual Studio Code | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Incomplete list of disallowed inputs in Visual Studio Code allows an unauthorized attacker to bypass a security feature locally.
- Vendors
- microsoft
- Products
- visual studio code
- Weakness
- CWE-184
- Vector
- CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.