ZeroHour

CVE-2026-78461

mass

Path Traversal in Microsoft Visual Studio Code Bypasses Security Feature

CVSS 3.1
7.4 high
EPSS
1%p63
Published
()
Modified
AI analysis

CVE-2026-78461 is a path traversal vulnerability (CWE-22) in Microsoft Visual Studio Code in which an improperly restricted pathname allows access to files outside a restricted directory. Per the CVSS vector, it is exploited over a network without authentication or privileges, but it requires user interaction — the user must be induced to open attacker-controlled content. A successful attack bypasses a VS Code security feature and yields high-impact unauthorized read access (confidentiality only, no integrity or availability impact), crossing a trust boundary to reach data the feature is designed to confine. All Visual Studio Code users are potentially affected; the affected and fixed version ranges are not specified in the available data. There is no known exploitation, no public proof-of-concept, and it is not in CISA's KEV catalog; EPSS estimates roughly a 1.1% probability of exploitation in the next 30 days (62nd percentile).

What to do: Update Visual Studio Code to the patched release identified in Microsoft's advisory once the fixed version is published (the current version is visible under Help > About). Until patched, avoid opening untrusted files, folders, or links in VS Code, and keep Workspace Trust/restricted mode enabled to limit access to trusted directories.

Affected
Microsoft Visual Studio Code
Estimated exposure
masstens of millions of developer installations (VS Code is the most widely used desktop code editor) — Public developer surveys consistently rank VS Code as the dominant desktop code editor with a large majority market share, implying an install base well above one million, though practical exploitability is limited to users who open…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Improper limitation of a pathname to a restricted directory ('path traversal') in Visual Studio Code allows an unauthorized attacker to bypass a security feature over a network.

Vendors
microsoft
Products
visual studio code
Weakness
CWE-22
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:N/A:N

In the news

No ingested article mentions this CVE yet.