CVE-2026-78461: Visual Studio Code Security Feature Bypass Vulnerability
Improper limitation of a pathname to a restricted directory ('path traversal') in Visual Studio Code allows an unauthorized attacker to bypass a security feature over a network.
Other sources
Visual Studio Code Security Feature Bypass Vulnerability
— Microsoft
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 1.136.2
Event History
Frequently Asked Questions
What level of access does an attacker need to exploit this issue?
The vector indicates network reachability and no privileges are required. Exploitation does require user interaction.
What security impact is identified?
The issue can bypass a security feature and has high confidentiality impact. The supplied vector indicates no integrity or availability impact.
Is exploit code or a remediation status provided?
No exploit code details or specific fixed versions are provided in the available data. The remediation level is listed as official fix available.