ZeroHour

CVE-2026-70334

mass

Local security-feature bypass in Microsoft Visual Studio Code

CVSS 3.1
7.8 high
EPSS
<1%p37
Published
()
Modified
AI analysis

CVE-2026-70334 is an incomplete list of disallowed inputs (CWE-184) in Microsoft Visual Studio Code, meaning the editor fails to block certain inputs and an attacker can thereby circumvent one of its built-in security features. Per the CVSS vector (AV:L/AC:L/PR:N/UI:R), exploitation requires local access plus user interaction: an unauthorized local attacker would need a user to open or act on crafted content in VS Code, after which the unfiltered input bypasses the security check. A successful bypass carries high impact on confidentiality, integrity, and availability of the local system (CVSS 3.1 score of 7.8 High), though the available description does not specify which security feature is affected. Anyone running Visual Studio Code is potentially affected; no affected or fixed version numbers were included in the source data. There is currently no known exploitation: no public proof-of-concept exists, the flaw is not in CISA's KEV catalog, and EPSS puts the 30-day exploitation probability at just 0.4%.

What to do: Update Visual Studio Code to the latest release from Microsoft, which addresses the incomplete input blocklist; since the flaw requires user interaction, exercise caution when opening files, folders, or workspaces from untrusted local sources. Because the attack is local, standard endpoint hygiene (limiting local attacker access) limits practical exposure.

Affected
Microsoft Visual Studio Code
Estimated exposure
massTens of millions of users (VS Code is the world's most-used code editor) — Visual Studio Code consistently ranks as the most popular developer editor (roughly 70%+ usage in Stack Overflow Developer Surveys) and Microsoft has reported tens of millions of monthly active users, though only endpoints where an…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Incomplete list of disallowed inputs in Visual Studio Code allows an unauthorized attacker to bypass a security feature locally.

Vendors
microsoft
Products
visual studio code
Weakness
CWE-184
Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.