CVE-2025-65715: Code Injection
Published Feb 16, 2026
·Updated
An issue in the code-runner.executorMap setting of Visual Studio Code Extensions Code Runner v0.12.2 allows attackers to execute arbitrary code when opening a crafted workspace.
Affected Software
2 affected components
vscode/CodeRunner
Formulahendry Coderunner Visual Studio Code>=0.12.2
Event History
Feb 16, 2026
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·04:19 PM
DescriptionSeverityWeaknessAffected Software
Feb 17, 2026
News Published
via BleepingComputer·09:27 PM
News Published
via BleepingComputer·09:29 PM
Frequently Asked Questions
1
What is the severity of CVE-2025-65715?
CVE-2025-65715 is classified as a critical vulnerability due to its potential to allow arbitrary code execution.
2
How do I fix CVE-2025-65715?
To fix CVE-2025-65715, upgrade the Code Runner extension to the latest version that addresses this vulnerability.
3
What are the consequences of CVE-2025-65715 in Visual Studio Code?
CVE-2025-65715 can lead to unauthorized execution of code, potentially compromising system security and user data.
4
Which versions of Code Runner are affected by CVE-2025-65715?
CVE-2025-65715 affects Code Runner version 0.12.2 and possibly earlier versions.
5
Can CVE-2025-65715 be exploited remotely?
Yes, CVE-2025-65715 can be exploited remotely when a crafted workspace is opened by a user.