CVE-2026-81357: Visual Studio Code Security Feature Bypass Vulnerability
Server-side request forgery (ssrf) in Visual Studio Code allows an unauthorized attacker to bypass a security feature over a network.
Other sources
Visual Studio Code Security Feature Bypass Vulnerability
— Microsoft
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 1.136.2
Event History
Frequently Asked Questions
What level of attacker access is required to exploit this issue?
The vector is network-based, attack complexity is low, and no privileges are required. However, user interaction is required for exploitation.
What impact could successful exploitation have?
The vulnerability is rated high severity with a CVSS score of 8.2. It can bypass a security feature and has high confidentiality impact and low integrity impact; availability impact is listed as none.
Is there evidence that this vulnerability is being exploited in the wild?
The provided exploit maturity rating is E:U, indicating exploit code is unproven. The data does not state that active exploitation has been observed.