CVE-2026-70336

8.8

Microsoft · Visual Studio Code

A code injection vulnerability in Visual Studio Code allows an unauthenticated attacker to execute arbitrary code over a network via malicious user interaction.

Executive summary

A code injection vulnerability in Visual Studio Code could enable an unauthenticated attacker to execute arbitrary code on a user's machine.

Vulnerability

This vulnerability is a code injection flaw, identified as CWE-94. It permits an unauthenticated attacker to execute code, typically requiring the user to open a specially crafted project or file.

Business impact

The CVSS score of 8.8 reflects the high potential impact of this vulnerability. If exploited, an attacker could gain full control over the developer's local machine, leading to the theft of source code, credentials, or lateral movement within the developer's network environment.

Remediation

Immediate Action: Update Visual Studio Code to version 1.132.1 or later immediately.

Proactive Monitoring: Monitor developer workstations for unusual execution patterns or unauthorized modifications to sensitive configuration files.

Compensating Controls: Advise developers to exercise caution when opening projects from untrusted sources and maintain up-to-date endpoint security software.

Exploitation status

Public Exploit Available: No

Analyst recommendation

Visual Studio Code is a high-value target for attackers aiming to compromise development environments. Organizations should mandate the update to version 1.132.1 to ensure that developer workstations remain protected against potential code injection attacks.

More Microsoft CVEs