ZeroHour

CVE-2026-81357

mass

SSRF Security-Feature Bypass in Microsoft Visual Studio Code

CVSS 3.1
8.2 high
EPSS
<1%p22
Published
()
Modified
AI analysis

CVE-2026-81357 is a server-side request forgery (SSRF, CWE-918) in Microsoft Visual Studio Code that lets an unauthenticated network attacker bypass one of the product's security features. Triggering likely requires user interaction (per the CVSS UI:R metric), such as coaxing a user into loading attacker-influenced content or a link that the application then fetches, with the forged request escaping the built-in request restrictions. A successful attack can reach otherwise protected network resources, with high confidentiality impact and limited integrity impact according to the CVSS scoring. All Visual Studio Code users are potentially affected, though the available data does not specify affected or fixed version ranges. Exploitation has not been observed: there is no known public proof-of-concept, the flaw is not in CISA KEV, and EPSS puts near-term exploitation probability at only 0.3% (22nd percentile).

What to do: Update Visual Studio Code to the latest release via the built-in update mechanism or Microsoft's download page, and verify your installed build against the version ranges listed in Microsoft's advisory. Until patched, exercise caution when opening untrusted links, files, or workspace content in VS Code. Monitor for public proof-of-concept code given the high severity rating despite currently low exploitation indicators.

Affected
Microsoft Visual Studio Code
Estimated exposure
masstens of millions of developer installations (VS Code is among the most widely used code editors, with tens of millions of monthly active users) — Visual Studio Code has an extremely large install base (Microsoft has publicly reported tens of millions of monthly active users, and it leads code-editor market share), so without version scoping essentially all current installs are…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Server-side request forgery (ssrf) in Visual Studio Code allows an unauthorized attacker to bypass a security feature over a network.

Vendors
microsoft
Products
visual studio code
Weakness
CWE-918
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N

In the news

No ingested article mentions this CVE yet.