CVE-2026-81357
massSSRF Security-Feature Bypass in Microsoft Visual Studio Code
CVE-2026-81357 is a server-side request forgery (SSRF, CWE-918) in Microsoft Visual Studio Code that lets an unauthenticated network attacker bypass one of the product's security features. Triggering likely requires user interaction (per the CVSS UI:R metric), such as coaxing a user into loading attacker-influenced content or a link that the application then fetches, with the forged request escaping the built-in request restrictions. A successful attack can reach otherwise protected network resources, with high confidentiality impact and limited integrity impact according to the CVSS scoring. All Visual Studio Code users are potentially affected, though the available data does not specify affected or fixed version ranges. Exploitation has not been observed: there is no known public proof-of-concept, the flaw is not in CISA KEV, and EPSS puts near-term exploitation probability at only 0.3% (22nd percentile).
What to do: Update Visual Studio Code to the latest release via the built-in update mechanism or Microsoft's download page, and verify your installed build against the version ranges listed in Microsoft's advisory. Until patched, exercise caution when opening untrusted links, files, or workspace content in VS Code. Monitor for public proof-of-concept code given the high severity rating despite currently low exploitation indicators.
| Microsoft Visual Studio Code | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Server-side request forgery (ssrf) in Visual Studio Code allows an unauthorized attacker to bypass a security feature over a network.
- Vendors
- microsoft
- Products
- visual studio code
- Weakness
- CWE-918
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N
In the news0 stories
No ingested article mentions this CVE yet.