product of microsoft

visual studio code

21 thingsrelated by NVD

Being told

Watch: its feed Ask more of it

The feed says each thing that enters, leaves or changes; a reader adds its address, /zetlyn/trackers/cve/things.atom?q=…, to theirs.

Every thing

Use of incorrectly-resolved name or reference in Visual Studio Code allows an unauthorized attacker to disclose information over a network.
CVE-2026-81383
Severity high
Insufficiently protected credentials in GitHub Copilot and Visual Studio Code allows an unauthorized attacker to disclose information over…
CVE-2026-81381
Severity high
Improper neutralization of special elements used in a command ('command injection') in GitHub Copilot and Visual Studio Code allows an…
CVE-2026-81380
Severity medium
Not failing securely ('failing open') in Visual Studio Code allows an unauthorized attacker to bypass a security feature over a network.
CVE-2026-81379
Severity high
Interpretation conflict in Visual Studio Code allows an unauthorized attacker to bypass a security feature over a network.
CVE-2026-81378
Severity high
Improper limitation of a pathname to a restricted directory ('path traversal') in Visual Studio Code allows an unauthorized attacker to…
CVE-2026-81377
Severity medium
Incomplete comparison with missing factors in Visual Studio Code allows an unauthorized attacker to bypass a security feature over a…
CVE-2026-81376
Severity critical
Server-side request forgery (ssrf) in Visual Studio Code allows an unauthorized attacker to bypass a security feature over a network.
CVE-2026-81357
Severity high
Inconsistent interpretation of http requests ('http request/response smuggling') in Visual Studio Code allows an unauthorized attacker to…
CVE-2026-81356
Severity high
Authorization bypass through user-controlled key in Visual Studio Code allows an unauthorized attacker to bypass a security feature over a…
CVE-2026-78462
Severity high
Improper limitation of a pathname to a restricted directory ('path traversal') in Visual Studio Code allows an unauthorized attacker to…
CVE-2026-78461
Severity high
Improper control of generation of code ('code injection') in Visual Studio Code allows an unauthorized attacker to execute code over a…
CVE-2026-70336
Severity high
Improper neutralization of special elements used in an os command ('os command injection') in GitHub Copilot and Visual Studio Code allows…
CVE-2026-70335
Severity high
Incomplete list of disallowed inputs in Visual Studio Code allows an unauthorized attacker to bypass a security feature locally.
CVE-2026-70334
Severity high
Improper neutralization of special elements used in an os command ('os command injection') in Visual Studio Code allows an unauthorized…
CVE-2026-69320
Severity high
Not failing securely ('failing open') in Visual Studio Code allows an unauthorized attacker to bypass a security feature over a network.
CVE-2026-69306
Severity high
Incorrect authorization in Visual Studio Code allows an unauthorized attacker to bypass a security feature locally.
CVE-2026-69278
Severity high
No cwe for this issue in Visual Studio Code CoPilot Chat Extension allows an unauthorized attacker to bypass a security feature over a…
CVE-2026-65675
Severity medium
Missing authorization in Visual Studio Code allows an unauthorized attacker to execute code over a network.
CVE-2026-59113
Severity high
Authorization bypass through user-controlled key in Visual Studio Code allows an unauthorized attacker to bypass a security feature locally.
CVE-2026-58650
Severity high
Improper neutralization of special elements used in a command ('command injection') in Visual Studio Code allows an unauthorized attacker…
CVE-2026-47285
Severity medium