📦 Visual Studio Code

by Microsoft

🔍 What is Visual Studio Code?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2026-21523

HIGH CVSS 8.0 Feb 10, 2026

A time-of-check time-of-use race condition vulnerability in GitHub Copilot and Visual Studio allows authenticated attackers to execute arbitrary code remotely via network exploitation. This affects us...

CVE-2025-64660

HIGH CVSS 8.0 Nov 20, 2025

This vulnerability allows an authorized attacker to execute arbitrary code remotely on systems running vulnerable versions of GitHub Copilot and Visual Studio Code. Attackers can exploit improper acce...

CVE-2025-55319

HIGH CVSS 8.8 Sep 12, 2025

This vulnerability allows remote command injection in Agentic AI and Visual Studio Code, enabling unauthorized attackers to execute arbitrary code over a network. It affects systems running vulnerable...

CVE-2025-26631

HIGH CVSS 7.3 Mar 11, 2025

This vulnerability in Visual Studio Code allows an authorized attacker to execute arbitrary code with elevated privileges by exploiting an uncontrolled search path element. It affects users who have l...

CVE-2025-24042

HIGH CVSS 7.3 Feb 11, 2025

This vulnerability in Visual Studio Code's JS Debug Extension allows attackers to escalate privileges when debugging JavaScript applications. It affects developers using VS Code with the JS Debug exte...

CVE-2025-24039

HIGH CVSS 7.3 Feb 11, 2025

This CVE describes an elevation of privilege vulnerability in Visual Studio Code where an attacker could execute arbitrary code with higher privileges than intended. It affects users running Visual St...

CVE-2024-43601

HIGH CVSS 7.8 Oct 8, 2024

This vulnerability allows remote code execution in Visual Studio Code on Linux systems. Attackers can execute arbitrary code by exploiting improper neutralization of special elements used in a command...

CVE-2023-36742

HIGH CVSS 7.8 Sep 12, 2023

This vulnerability in Visual Studio Code allows remote code execution when a user opens a maliciously crafted file or project. It affects users who open untrusted files in Visual Studio Code, potentia...

CVE-2023-24893

HIGH CVSS 7.8 Apr 11, 2023

CVE-2023-24893 is a remote code execution vulnerability in Visual Studio Code that allows attackers to execute arbitrary code on a user's system by tricking them into opening a malicious workspace fil...

CVE-2022-30129

HIGH CVSS 8.8 May 10, 2022

This vulnerability allows remote code execution in Visual Studio Code through argument injection in the 'code' command-line tool. Attackers can craft malicious arguments that execute arbitrary command...

CVE-2022-26921

HIGH CVSS 7.3 Apr 15, 2022

CVE-2022-26921 is an elevation of privilege vulnerability in Visual Studio Code that allows attackers to execute arbitrary code with higher privileges than intended. This affects users running Visual ...

CVE-2022-21991

HIGH CVSS 8.1 Feb 9, 2022

This vulnerability allows remote code execution through Visual Studio Code's Remote Development extension. Attackers can execute arbitrary code on systems running vulnerable versions when users connec...

CVE-2021-43891

HIGH CVSS 7.8 Dec 15, 2021

CVE-2021-43891 is a remote code execution vulnerability in Visual Studio Code that allows attackers to execute arbitrary code by tricking users into opening malicious workspace files. This affects use...

CVE-2021-34528

HIGH CVSS 7.8 Jul 14, 2021

This vulnerability in Visual Studio Code allows remote code execution when a user opens a maliciously crafted file or project. It affects users who open untrusted files in Visual Studio Code, particul...

CVE-2021-34479

HIGH CVSS 7.8 Jul 14, 2021

CVE-2021-34479 is a spoofing vulnerability in Microsoft Visual Studio that allows attackers to trick users into executing malicious code by presenting a deceptive UI. This affects developers and organ...

CVE-2021-31211

HIGH CVSS 7.8 May 11, 2021

This vulnerability in Visual Studio Code allows remote code execution when a user opens a maliciously crafted file or workspace. It affects users who open untrusted files in Visual Studio Code, potent...

CVE-2021-31214

HIGH CVSS 7.8 May 11, 2021

CVE-2021-31214 is a remote code execution vulnerability in Visual Studio Code that allows attackers to execute arbitrary code on a user's system by tricking them into opening a malicious workspace fil...

CVE-2021-28471

HIGH CVSS 7.8 Apr 13, 2021

This vulnerability in the Visual Studio Code Remote Development extension allows attackers to execute arbitrary code on a developer's machine when they connect to a malicious remote endpoint. It affec...

CVE-2021-28473

HIGH CVSS 7.8 Apr 13, 2021

This vulnerability in Visual Studio Code allows remote code execution when a user opens a maliciously crafted file or workspace. Attackers can exploit this to execute arbitrary code on the victim's sy...

CVE-2021-28477

HIGH CVSS 7.0 Apr 13, 2021

CVE-2021-28477 is a remote code execution vulnerability in Visual Studio Code that allows attackers to execute arbitrary code on a user's system by tricking them into opening a malicious workspace fil...

CVE-2021-28457

HIGH CVSS 7.8 Apr 13, 2021

This vulnerability in Visual Studio Code allows remote code execution when a user opens a maliciously crafted file or project. It affects users who open untrusted files in VS Code, potentially allowin...

CVE-2021-28469

HIGH CVSS 7.8 Apr 13, 2021

This vulnerability in Visual Studio Code allows remote code execution when a user opens a maliciously crafted file or project. It affects users who open untrusted files in Visual Studio Code, potentia...

CVE-2020-17023

HIGH CVSS 7.8 Oct 16, 2020

This CVE describes a remote code execution vulnerability in Visual Studio Code where opening a malicious package.json file allows arbitrary code execution. It affects Visual Studio Code users who open...

CVE-2020-16881

HIGH CVSS 7.8 Sep 11, 2020

This is a remote code execution vulnerability in Visual Studio Code where opening a malicious 'package.json' file allows arbitrary code execution. It affects Visual Studio Code users who open untruste...

CVE-2020-0604

HIGH CVSS 7.8 Aug 17, 2020

A remote code execution vulnerability in Visual Studio Code allows attackers to run arbitrary code when users open malicious repositories and use the integrated terminal. This affects all Visual Studi...

CVE-2025-62453

MEDIUM CVSS 5.0 Nov 11, 2025

This vulnerability allows an authorized attacker to bypass local security features in GitHub Copilot and Visual Studio Code by exploiting improper validation of generative AI output. It affects users ...

CVE-2025-32726

MEDIUM CVSS 6.8 Apr 12, 2025

This vulnerability in Visual Studio Code allows an authenticated local attacker to bypass access controls and gain elevated privileges on the system. It affects users running vulnerable versions of VS...