CVE-2026-81376
mass1Security Feature Bypass in Microsoft Visual Studio Code
CVE-2026-81376 is a critical security feature bypass in Microsoft Visual Studio Code caused by an incomplete comparison with missing factors (CWE-1023), resulting in a protection mechanism failure (CWE-693). The flaw is reachable over a network and exploitation requires user interaction (per the CVSS vector), such as inducing a user to act on attacker-controlled content, after which an unprivileged attacker can bypass the affected security check. The changed-scope metric indicates the bypass can cross a component boundary, and the high confidentiality, integrity and availability ratings mean a successful bypass can have serious consequences beyond weakening a single control. Everyone running Visual Studio Code is potentially affected; the available data does not specify the vulnerable version ranges or the fixing release. Exploitation has not been observed: no public proof-of-concept is known, the flaw is not in CISA's KEV, and EPSS estimates only about a 0.7% chance of exploitation in the next 30 days.
What to do: Monitor Microsoft's advisory for the fixed release and update Visual Studio Code as soon as a patched version is published, since no version numbers are available yet. Until then, exercise caution with untrusted files, repositories and prompts (user interaction is part of the attack vector), and prioritize scheduling the update given the 9.6 critical CVSS despite no known exploitation.
| Microsoft Visual Studio Code | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Incomplete comparison with missing factors in Visual Studio Code allows an unauthorized attacker to bypass a security feature over a network.
- Vendors
- microsoft
- Products
- visual studio code
- Weakness
- CWE-693, CWE-1023
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.