Known Vulnerabilities for Visual Studio Code by Microsoft
Listed below are 10 of the newest known vulnerabilities associated with "Visual Studio Code" by "Microsoft".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-41613 json | Session fixation in Visual Studio Code allows an unauthorized attacker to elevate privileges over a network. | Not Provided | 2026-05-12 | 2026-05-12 |
| CVE-2026-41612 json | Relative path traversal in Visual Studio Code allows an unauthorized attacker to disclose information locally. | Not Provided | 2026-05-12 | 2026-05-12 |
| CVE-2026-41611 json | Improper neutralization of script-related html tags in a web page (basic xss) in Visual Studio Code allows an unauthorized at... | Not Provided | 2026-05-12 | 2026-05-12 |
| CVE-2026-41610 json | Improper neutralization of input during web page generation ('cross-site scripting') in Visual Studio Code allows an unauthor... | Not Provided | 2026-05-12 | 2026-05-12 |
| CVE-2026-32732 json | Lean 4 VS Code Extension is a Visual Studio Code extension for the Lean 4 proof assistant. Projects that use @leanprover/unic... | Not Provided | 2026-03-16 | 2026-03-16 |
| CVE-2026-23653 json | Improper neutralization of special elements used in a command ('command injection') in GitHub Copilot and Visual Studio Code ... | Not Provided | 2026-04-14 | 2026-04-30 |
| CVE-2025-65717 json | An issue in Visual Studio Code Extensions Live Server v5.7.9 allows attackers to exfiltrate files via user interaction with a... | Not Provided | 2026-02-16 | 2026-05-05 |
| CVE-2023-36742 json | Visual Studio Code Remote Code Execution Vulnerability | 7.8 - HIGH | 2023-09-12 | 2023-09-14 |
| CVE-2023-33144 json | Visual Studio Code Spoofing Vulnerability | 6.6 - MEDIUM | 2023-06-14 | 2023-08-01 |
| CVE-2023-29338 json | Visual Studio Code Spoofing Vulnerability | 6.6 - MEDIUM | 2023-05-09 | 2023-10-12 |
Known Affected Configurations (CPE V2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Microsoft | Visual Studio Code | 2020.5.80290 | |||
| Application | Microsoft | Visual Studio Code | 2020.5.78807 | |||
| Application | Microsoft | Visual Studio Code | 2020.5.0 | |||
| Application | Microsoft | Visual Studio Code | 2020.4.76186 | |||
| Application | Microsoft | Visual Studio Code | 2020.4.74986 | |||
| Application | Microsoft | Visual Studio Code | 2020.3.71659 | |||
| Application | Microsoft | Visual Studio Code | 2020.3.71113 | |||
| Application | Microsoft | Visual Studio Code | 2020.3.69010 | |||
| Application | Microsoft | Visual Studio Code | 2020.2.64397 | |||
| Application | Microsoft | Visual Studio Code | 2020.2.63990 | |||
| Application | Microsoft | Visual Studio Code | 2020.2.63072 | |||
| Application | Microsoft | Visual Studio Code | 2020.2.62710 | |||
| Application | Microsoft | Visual Studio Code | 2020.1.58038 | |||
| Application | Microsoft | Visual Studio Code | 2020.1.57204 | |||
| Application | Microsoft | Visual Studio Code | 2019.9.34911 | |||
| Application | Microsoft | Visual Studio Code | 2019.9.34474 | |||
| Application | Microsoft | Visual Studio Code | 2019.8.30787 | |||
| Application | Microsoft | Visual Studio Code | 2019.8.29288 | |||
| Application | Microsoft | Visual Studio Code | 2019.6.24221 | |||
| Application | Microsoft | Visual Studio Code | 2019.6.22090 |