CVE-2026-81379: Visual Studio Code Security Feature Bypass Vulnerability
Not failing securely ('failing open') in Visual Studio Code allows an unauthorized attacker to bypass a security feature over a network.
Other sources
Visual Studio Code Security Feature Bypass Vulnerability
— Microsoft
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 1.136.2
Event History
Frequently Asked Questions
What does an attacker need to exploit this issue?
The attack vector is network-based, requires no privileges, and has low attack complexity. User interaction is required for exploitation.
What is the potential impact if exploitation succeeds?
Successful exploitation can bypass a security feature and may result in high confidentiality impact and low integrity impact. Availability impact is listed as none.
Is there evidence that this vulnerability is being exploited in the wild?
The provided exploit code maturity rating is unproven (E:U). The data does not indicate confirmed active exploitation.