CVE-2026-81377: Visual Studio Code Tampering Vulnerability
Published Sep 8, 2026
·Updated
Improper limitation of a pathname to a restricted directory ('path traversal') in Visual Studio Code allows an unauthorized attacker to perform tampering over a network.
Other sources
Visual Studio Code Tampering Vulnerability
— Microsoft
Affected Software
1 affected componentFixes available
Microsoft Visual Studio Code<1.136.2
1.136.2
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 1.136.2
Event History
Sep 8, 2026
CVE Published
via Microsoft·02:00 PM
Data Sourced
via Microsoft·02:00 PM
DescriptionSeverityWeakness
Data Sourced
via Microsoft·02:00 PM
Affected Software
Updated
via Microsoft·02:00 PM
Description
CVE Published
via MITRE·05:13 PM
Data Sourced
via MITRE·05:13 PM
DescriptionSeverity
Frequently Asked Questions
1
What level of access does an attacker need?
The vector is network-based and requires no privileges, but exploitation requires user interaction.
2
What is the likely security impact?
The stated impact is tampering: integrity may be affected, while confidentiality and availability are not listed as affected.
3
Is there evidence of active exploitation or a known fix?
The available data marks exploit maturity as unknown and remediation level as an official fix, but it does not identify affected or fixed versions.