CVE-2026-81383
massInformation Disclosure via Incorrect Name Resolution in Microsoft Visual Studio Code
CVE-2026-81383 is an information-disclosure flaw in Microsoft Visual Studio Code caused by the application using incorrectly-resolved names or references (CWE-706). Per the CVSS vector, exploitation is remote and low-complexity, requires no privileges or authentication, but does require user interaction (e.g., a user being induced to open attacker-influenced content such as a crafted workspace, file, or link), and it crosses a security boundary (changed scope). A successful attack lets an unauthorized remote attacker read sensitive information over the network, with high confidentiality impact and no integrity or availability impact. All Visual Studio Code users are potentially affected; the available data does not specify affected version ranges, so defenders should consult Microsoft's advisory for exact ranges. No public proof-of-concept or in-the-wild exploitation is known, and EPSS assigns a modest 0.7% probability of exploitation within 30 days.
What to do: Check Microsoft's security advisory for CVE-2026-81383 and update Visual Studio Code to the fixed release as soon as it is available (affected/fixed version ranges were not included in the data provided). Until updated, apply caution with untrusted content: rely on Workspace Trust and avoid opening untrusted workspaces, files, or links. No exploitation is currently known, but monitor Microsoft's advisory and CISA feeds for updates.
| Microsoft Visual Studio Code | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Use of incorrectly-resolved name or reference in Visual Studio Code allows an unauthorized attacker to disclose information over a network.
- Vendors
- microsoft
- Products
- visual studio code
- Weakness
- CWE-706
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:N/A:N
In the news0 stories
No ingested article mentions this CVE yet.