Catalog / Visual Studio Code

Visual Studio Code security advisories

All 43 advisories Visual Studio Code has published with an identifier, newest first. Severity is the one its publisher assigned, and the fix is the release the publisher named. Nothing on this page is our judgement.

Advisories
4343 carry a CVE
high
34
medium
7
low
2
Fix in the archive
0of 43 matched to a release
Oldest
25 May 20224.3 years ago

43 of these point at a version older than anything the archive holds, so there is no release page to link. That is a gap in what was collected, not evidence that the fix does not exist. This page is a copy of what the publisher published, kept for reference. The authoritative source for a security question is the publisher, and an advisory missing from here is not evidence that none exists. What this page does and does not tell you sets out the limits in full.

Newest first

Every product
CVE-2026-69306high

Agent network filter bypass via IPv4-mapped IPv6 literals

GHSA-6xp2-9cj3-f488Fixed in 1.132.1, not held here
CVE-2026-59113high

Fetch Web Page OS protocol handler remote code execution

GHSA-36qf-jgq9-4m6jFixed in 1.132.1, not held here
CVE-2026-58650high

TerminalInstance._createProcess() - Local RCE via extensions.json recommendation link

GHSA-h6v9-3cqc-v234Fixed in 1.132.1, not held here
CVE-2026-69320high

Visual Studio Code web deployments - environmentService.ts - RCE via NODE_OPTIONS --import from URL payload

GHSA-h29r-p8vr-4vfmFixed in 1.132.1, not held here
CVE-2026-69278high

TerminalInstance._createProcess - Workspace Trust bypass via terminal waitOnExit

GHSA-h9j4-x76r-fvj4Fixed in 1.132.1, not held here
CVE-2026-70335high

Copilot Custom Agent Hook Remote Code Execution Vulnerability

GHSA-w79w-rj9h-vg4fFixed in 1.132.1, not held here
CVE-2026-70336high

Fileless RCE in VS Code Web Remote Terminal via URL-Controlled NODE_OPTIONS

GHSA-fp6w-v29h-43rjFixed in 1.132.1, not held here
CVE-2026-47285medium

Information disclosure vulnerability

GHSA-vcpf-2mpp-vx3vFixed in 1.132.1, not held here
CVE-2026-65675high

Copilot Chat Security Feature Bypass Vulnerability

GHSA-3hjg-cwxj-qfc6Fixed in 1.132.1, not held here
CVE-2026-57102high

Remote Code Execution Vulnerability

GHSA-v282-cxqj-xgj4Fixed in 1.128.1, not held here
CVE-2026-57101high

Workspace Trust Security Feature Bypass Vulnerability

GHSA-9mw4-h26x-gfxwFixed in 1.128.1, not held here
CVE-2026-47282high

Secret exfiltration vulnerability

GHSA-wr9x-42j2-jvh3Fixed in 1.128.1, not held here
CVE-2026-47281high

Unconfirmed Remote Host Connection via Workspace File

GHSA-5j3g-c7qg-xfvxFixed in 1.123.1, not held here
CVE-2026-45482low

Auto-Approved File Write via Unconfirmed Environment-Variable Path Redirection

GHSA-c82g-9gj4-hxp2Fixed in 1.123.1, not held here
CVE-2026-47287medium

Path traversal in profile snippets import allows writing files outside the profile directory (Zip-Slip)

GHSA-hgwg-xqr5-q87fFixed in 1.123.1, not held here
CVE-2026-47284high

GitHubCredentialProvider - Regex substring host match sends Basic-auth tokens

GHSA-qcxw-jfff-cxpcFixed in 1.123.1, not held here
CVE-2026-41610medium

Remote Code Execution Vulnerability with Jupyter notebook markdown rendering in untrusted workspaces

GHSA-v32f-vf7g-ggmwFixed in 1.119.1, not held here
CVE-2026-41611medium

Remote Code Execution Vulnerability in webviews

GHSA-5vj9-2628-2rm4Fixed in 1.119.1, not held here
CVE-2026-41109high

Apply patch sensitive file workaround

GHSA-rg3f-8xq5-hwh6
CVE-2026-41613high

MCP Deeplink Install Lacked Essential Information

GHSA-9f6c-63gp-pwpf
CVE-2026-21518low

Workspace trust for MCP servers

GHSA-6xq8-9qf3-p6qvFixed in 1.109.1, not held here
CVE-2026-21523high

apply_patch sensitive file bypass

GHSA-w79r-pmq3-8v4fFixed in 0.37.3, not held here
CVE-2026-21523high

URL unicode escaping

GHSA-g84c-g4wq-2pwpFixed in 0.37.3, not held here
CVE-2026-21523high

Terminal auto replies restriction

GHSA-3pwg-f3hj-wp8pFixed in 1.109.1, not held here
CVE-2025-21264high

Security Feature Bypass Vulnerability

GHSA-742r-ggwg-vqxmFixed in 1.100.1, not held here
CVE-2025-20570high

Remote Code Execution Vulnerability

GHSA-hwrx-jgf2-74hwFixed in 1.99.1, not held here
CVE-2025-24039high

Elevation of Privilege Vulnerability

GHSA-532g-4pv9-25f2Fixed in 1.97.1, not held here
CVE-2025-24042medium

Elevation of Privilege Vulnerability

GHSA-f85p-3684-2g3jFixed in 1.97.1, not held here
CVE-2024-43601high

Visual Studio Code for Linux Remote Code Execution Vulnerability

GHSA-g56j-w527-8x6fFixed in 1.94.1, not held here
CVE-2024-26165high

Elevation of Privilege Vulnerability

GHSA-54p6-6j68-j5vrFixed in 1.87.2, not held here
CVE-2023-39956high

Remote Code Execution Vulnerability

GHSA-5cm6-54wm-6gg6Fixed in 1.80.2, not held here
CVE-2023-36742high

Remote Code Execution Vulnerability

GHSA-r6q2-478f-5gmrFixed in 1.82.1, not held here
CVE-2023-33144high

Information Disclosure Vulnerability

GHSA-j5wm-6crw-xvmrFixed in 1.79.1, not held here
CVE-2023-29338high

Information Disclosure Vulnerability

GHSA-mmfh-4pv3-39hrFixed in 1.78.1, not held here
CVE-2023-24893high

Remote Code Execution Vulnerability

GHSA-4v3r-wv86-6mjjFixed in 1.77.1, not held here
CVE-2023-21779medium

Remote Code Execution Vulnerability

GHSA-p996-wrgh-crrjFixed in 1.74.3, not held here
CVE-2022-41034high

Remote Code Execution Vulnerability

GHSA-q6rv-h25q-6pj6Fixed in 1.71.1, not held here
CVE-2022-41042medium

Information Disclosure Vulnerability

GHSA-fj7x-w8c2-xx4cFixed in 1.71.1, not held here
CVE-2022-38020high

Elevation of Privilege Vulnerability

GHSA-6c5x-m47q-5xmfFixed in 1.71.1, not held here
CVE-2022-30129high

Remote Code Execution Vulnerability

GHSA-jfjw-mv65-hg44Fixed in 1.67.1, not held here
CVE-2022-26921high

Elevation of Privilege Vulnerability

GHSA-wrm3-w8h4-q8mxFixed in 1.66.2, not held here
CVE-2022-24526high

Spoofing Vulnerability

GHSA-9rwm-gmc5-vhrfFixed in 1.65.1, not held here
CVE-2022-21991high

Remote Code Execution Vulnerability

GHSA-5q6q-39p2-37cxFixed in 1.64.1, not held here