CVE-2026-81378
massSecurity Feature Bypass via Interpretation Conflict in Microsoft Visual Studio Code
CVE-2026-81378 is an interpretation conflict (CWE-436) in Microsoft Visual Studio Code in which different components interpret the same input differently, allowing an unauthorized attacker to bypass a security feature over a network. Per the CVSS vector, exploitation requires user interaction (for example, a victim opening attacker-influenced content), involves a scope change, and yields a high-impact confidentiality breach with low integrity impact and no availability impact. Any environment running Visual Studio Code is potentially affected, although the specific affected version ranges are not provided in the available data and must be confirmed against Microsoft's advisory. There is currently no known exploitation: no public proof-of-concept exists, the flaw is not in CISA's KEV, and EPSS assigns only a 0.3% probability of exploitation within 30 days.
What to do: Update Visual Studio Code to the latest patched build as identified in Microsoft's security advisory, since the affected and fixed version ranges are not stated in the available data. Until patched, exercise caution when opening untrusted workspaces, repositories, or files obtained over the network, and review Microsoft's guidance on which security feature is affected. Given the high CVSS severity, monitor the advisory for added exploitation evidence or a KEV listing.
| Microsoft Visual Studio Code | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Interpretation conflict in Visual Studio Code allows an unauthorized attacker to bypass a security feature over a network.
- Vendors
- microsoft
- Products
- visual studio code
- Weakness
- CWE-436
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N
In the news0 stories
No ingested article mentions this CVE yet.