Agent network filter bypass via IPv4-mapped IPv6 literals
Visual Studio Code security advisories
All 43 advisories Visual Studio Code has published with an identifier, newest first. Severity is the one its publisher assigned, and the fix is the release the publisher named. Nothing on this page is our judgement.
- Advisories
- 4343 carry a CVE
- high
- 34
- medium
- 7
- low
- 2
- Fix in the archive
- 0of 43 matched to a release
- Oldest
- 25 May 20224.3 years ago
43 of these point at a version older than anything the archive holds, so there is no release page to link. That is a gap in what was collected, not evidence that the fix does not exist. This page is a copy of what the publisher published, kept for reference. The authoritative source for a security question is the publisher, and an advisory missing from here is not evidence that none exists. What this page does and does not tell you sets out the limits in full.
Newest first
Every productFetch Web Page OS protocol handler remote code execution
TerminalInstance._createProcess() - Local RCE via extensions.json recommendation link
Visual Studio Code web deployments - environmentService.ts - RCE via NODE_OPTIONS --import from URL payload
TerminalInstance._createProcess - Workspace Trust bypass via terminal waitOnExit
Copilot Custom Agent Hook Remote Code Execution Vulnerability
Fileless RCE in VS Code Web Remote Terminal via URL-Controlled NODE_OPTIONS
Information disclosure vulnerability
Copilot Chat Security Feature Bypass Vulnerability
Remote Code Execution Vulnerability
Workspace Trust Security Feature Bypass Vulnerability
Secret exfiltration vulnerability
Unconfirmed Remote Host Connection via Workspace File
Auto-Approved File Write via Unconfirmed Environment-Variable Path Redirection
Path traversal in profile snippets import allows writing files outside the profile directory (Zip-Slip)
GitHubCredentialProvider - Regex substring host match sends Basic-auth tokens
Remote Code Execution Vulnerability with Jupyter notebook markdown rendering in untrusted workspaces
Remote Code Execution Vulnerability in webviews
Apply patch sensitive file workaround
MCP Deeplink Install Lacked Essential Information
Workspace trust for MCP servers
apply_patch sensitive file bypass
URL unicode escaping
Terminal auto replies restriction
Security Feature Bypass Vulnerability
Remote Code Execution Vulnerability
Elevation of Privilege Vulnerability
Elevation of Privilege Vulnerability
Visual Studio Code for Linux Remote Code Execution Vulnerability
Elevation of Privilege Vulnerability
Remote Code Execution Vulnerability
Remote Code Execution Vulnerability
Information Disclosure Vulnerability
Information Disclosure Vulnerability
Remote Code Execution Vulnerability
Remote Code Execution Vulnerability
Remote Code Execution Vulnerability
Information Disclosure Vulnerability
Elevation of Privilege Vulnerability
Remote Code Execution Vulnerability
Elevation of Privilege Vulnerability
Spoofing Vulnerability
Remote Code Execution Vulnerability