CVE-2025-65717: XSS
Published Feb 16, 2026
·Updated
An issue in Visual Studio Code Extensions Live Server v5.7.9 allows attackers to exfiltrate files via user interaction with a crafted HTML page.
Affected Software
2 affected components
Microsoft Visual Studio Code Extensions Live Server
Ritwickdey Live Server Visual Studio Code>=5.7.9
Event History
Feb 16, 2026
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·04:19 PM
DescriptionSeverityWeaknessAffected Software
Feb 17, 2026
News Published
via BleepingComputer·09:27 PM
News Published
via BleepingComputer·09:29 PM
Frequently Asked Questions
1
What is the severity of CVE-2025-65717?
CVE-2025-65717 has a medium severity level due to its potential to allow file exfiltration from user systems.
2
How do I fix CVE-2025-65717?
To mitigate CVE-2025-65717, users should upgrade to the latest version of the Live Server extension.
3
What type of attack does CVE-2025-65717 exploit?
CVE-2025-65717 exploits vulnerabilities through user interaction with a crafted HTML page leading to file exfiltration.
4
Who is affected by CVE-2025-65717?
Users of Visual Studio Code Extensions Live Server version 5.7.9 are affected by CVE-2025-65717.
5
What is the main impact of CVE-2025-65717 on users?
The main impact of CVE-2025-65717 is the unauthorized exfiltration of files from a user's system.