CVE-2026-81379
massSecurity Feature Bypass (Fails-Open) in Microsoft Visual Studio Code
CVE-2026-81379 is a fails-open flaw (CWE-636) in Microsoft Visual Studio Code, meaning that when a security check fails, the product permits access instead of denying it, allowing an unauthorized attacker to bypass a security feature. The attack is carried out over a network and requires user interaction (CVSS UI:R), so a user must typically be induced to interact with attacker-influenced content for the bypass to occur. A successful attacker gains a bypass of a security feature with high confidentiality impact and low integrity impact (no availability impact), yielding a CVSS 3.1 base score of 8.2 (High). All users of Visual Studio Code are potentially affected, though the data provided does not specify which version ranges are vulnerable or fixed. Exploitation is not currently observed: there is no known public proof-of-concept, the flaw is not in CISA KEV, and EPSS estimates only a 0.3% chance of exploitation in the next 30 days.
What to do: Update Visual Studio Code to the latest release distributed via Microsoft's normal auto-update channel or the official download page, and check Microsoft's advisory for the exact affected and fixed versions since they are not specified in the provided data. In the meantime, exercise caution when opening untrusted repositories, workspaces, or links in VS Code, since the network vector requires user interaction. Given the low EPSS (0.3%) and absence of a public PoC, patching at the next regular update cycle is reasonable, but prioritize it for developer workstations handling sensitive source code.
| Microsoft Visual Studio Code | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Not failing securely ('failing open') in Visual Studio Code allows an unauthorized attacker to bypass a security feature over a network.
- Vendors
- microsoft
- Products
- visual studio code
- Weakness
- CWE-636
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N
In the news0 stories
No ingested article mentions this CVE yet.