CVE-2025-65716: Code Injection
Published Feb 16, 2026
·Updated
An issue in Visual Studio Code Extensions Markdown Preview Enhanced v0.8.18 allows attackers to execute arbitrary code via uploading a crafted .Md file.
Affected Software
2 affected components
Microsoft Visual Studio Code Extensions Markdown Preview Enhanced
Shd101wyy Markdown Preview Enhanced Visual Studio Code>=0.8.18
Event History
Feb 16, 2026
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·04:19 PM
DescriptionSeverityWeaknessAffected Software
Feb 17, 2026
News Published
via BleepingComputer·09:27 PM
News Published
via BleepingComputer·09:29 PM
Frequently Asked Questions
1
What is the severity of CVE-2025-65716?
CVE-2025-65716 has a high severity rating due to its potential to allow arbitrary code execution.
2
How do I fix CVE-2025-65716?
To fix CVE-2025-65716, update the Markdown Preview Enhanced extension to the latest version available.
3
What type of attack does CVE-2025-65716 facilitate?
CVE-2025-65716 facilitates code execution attacks via crafted .Md files uploaded by an attacker.
4
Which software is affected by CVE-2025-65716?
CVE-2025-65716 affects the Visual Studio Code Extensions Markdown Preview Enhanced version 0.8.18.
5
Who is the vendor responsible for CVE-2025-65716?
The vendor responsible for CVE-2025-65716 is Microsoft, specifically for the Visual Studio Code Extensions.