ZeroHour

CVE-2026-81383

mass

Information Disclosure via Incorrect Name Resolution in Microsoft Visual Studio Code

CVSS 3.1
7.4 high
EPSS
<1%p51
Published
()
Modified
AI analysis

CVE-2026-81383 is an information-disclosure flaw in Microsoft Visual Studio Code caused by the application using incorrectly-resolved names or references (CWE-706). Per the CVSS vector, exploitation is remote and low-complexity, requires no privileges or authentication, but does require user interaction (e.g., a user being induced to open attacker-influenced content such as a crafted workspace, file, or link), and it crosses a security boundary (changed scope). A successful attack lets an unauthorized remote attacker read sensitive information over the network, with high confidentiality impact and no integrity or availability impact. All Visual Studio Code users are potentially affected; the available data does not specify affected version ranges, so defenders should consult Microsoft's advisory for exact ranges. No public proof-of-concept or in-the-wild exploitation is known, and EPSS assigns a modest 0.7% probability of exploitation within 30 days.

What to do: Check Microsoft's security advisory for CVE-2026-81383 and update Visual Studio Code to the fixed release as soon as it is available (affected/fixed version ranges were not included in the data provided). Until updated, apply caution with untrusted content: rely on Workspace Trust and avoid opening untrusted workspaces, files, or links. No exploitation is currently known, but monitor Microsoft's advisory and CISA feeds for updates.

Affected
Microsoft Visual Studio Code
Estimated exposure
masstens of millions of developer installations/users (VS Code has tens of millions of monthly active users), though only a subset is exploitable because user… — Estimated from VS Code's dominant position as the most widely used desktop code editor, with tens of millions of monthly active users reported by Microsoft and industry developer surveys, while noting the interactive trigger limits the…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Use of incorrectly-resolved name or reference in Visual Studio Code allows an unauthorized attacker to disclose information over a network.

Vendors
microsoft
Products
visual studio code
Weakness
CWE-706
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:N/A:N

In the news

No ingested article mentions this CVE yet.