ZeroHour

CVE-2026-81378

mass

Security Feature Bypass via Interpretation Conflict in Microsoft Visual Studio Code

CVSS 3.1
8.2 high
EPSS
<1%p26
Published
()
Modified
AI analysis

CVE-2026-81378 is an interpretation conflict (CWE-436) in Microsoft Visual Studio Code in which different components interpret the same input differently, allowing an unauthorized attacker to bypass a security feature over a network. Per the CVSS vector, exploitation requires user interaction (for example, a victim opening attacker-influenced content), involves a scope change, and yields a high-impact confidentiality breach with low integrity impact and no availability impact. Any environment running Visual Studio Code is potentially affected, although the specific affected version ranges are not provided in the available data and must be confirmed against Microsoft's advisory. There is currently no known exploitation: no public proof-of-concept exists, the flaw is not in CISA's KEV, and EPSS assigns only a 0.3% probability of exploitation within 30 days.

What to do: Update Visual Studio Code to the latest patched build as identified in Microsoft's security advisory, since the affected and fixed version ranges are not stated in the available data. Until patched, exercise caution when opening untrusted workspaces, repositories, or files obtained over the network, and review Microsoft's guidance on which security feature is affected. Given the high CVSS severity, monitor the advisory for added exploitation evidence or a KEV listing.

Affected
Microsoft Visual Studio Code
Estimated exposure
masstens of millions of developer installations (VS Code is the most widely used code editor worldwide) — Visual Studio Code's dominant share in public developer usage surveys and tens of millions of monthly active users reported by Microsoft place the installed base plausibly an order of magnitude above one million.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Interpretation conflict in Visual Studio Code allows an unauthorized attacker to bypass a security feature over a network.

Vendors
microsoft
Products
visual studio code
Weakness
CWE-436
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N

In the news

No ingested article mentions this CVE yet.