CVE-2026-78461
massPath Traversal in Microsoft Visual Studio Code Bypasses Security Feature
CVE-2026-78461 is a path traversal vulnerability (CWE-22) in Microsoft Visual Studio Code in which an improperly restricted pathname allows access to files outside a restricted directory. Per the CVSS vector, it is exploited over a network without authentication or privileges, but it requires user interaction — the user must be induced to open attacker-controlled content. A successful attack bypasses a VS Code security feature and yields high-impact unauthorized read access (confidentiality only, no integrity or availability impact), crossing a trust boundary to reach data the feature is designed to confine. All Visual Studio Code users are potentially affected; the affected and fixed version ranges are not specified in the available data. There is no known exploitation, no public proof-of-concept, and it is not in CISA's KEV catalog; EPSS estimates roughly a 1.1% probability of exploitation in the next 30 days (62nd percentile).
What to do: Update Visual Studio Code to the patched release identified in Microsoft's advisory once the fixed version is published (the current version is visible under Help > About). Until patched, avoid opening untrusted files, folders, or links in VS Code, and keep Workspace Trust/restricted mode enabled to limit access to trusted directories.
| Microsoft Visual Studio Code | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Improper limitation of a pathname to a restricted directory ('path traversal') in Visual Studio Code allows an unauthorized attacker to bypass a security feature over a network.
- Vendors
- microsoft
- Products
- visual studio code
- Weakness
- CWE-22
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:N/A:N
In the news0 stories
No ingested article mentions this CVE yet.