CVE-2026-69320: Visual Studio Code Remote Code Execution Vulnerability
Improper neutralization of special elements used in an os command ('os command injection') in Visual Studio Code allows an unauthorized attacker to execute code over a network.
Other sources
Visual Studio Code Remote Code Execution Vulnerability
— Microsoft
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 1.132.1
Event History
Frequently Asked Questions
What is the severity of CVE-2026-69320?
CVE-2026-69320 has a high severity rating of 8.8.
How do I fix CVE-2026-69320?
To address CVE-2026-69320, update Microsoft Visual Studio Code to the latest version that includes the security patches.
What type of vulnerability is CVE-2026-69320?
CVE-2026-69320 is an OS Command Injection vulnerability that allows unauthorized code execution.
What could an attacker exploit in CVE-2026-69320?
An attacker could exploit CVE-2026-69320 to execute arbitrary code over a network.
Which software is affected by CVE-2026-69320?
CVE-2026-69320 specifically affects Microsoft Visual Studio Code.