Microsoft
Microsoft Visual Studio Code: vulnerabilidades y CVE
Microsoft Visual Studio Code tiene 98 vulnerabilidades publicadas, 48 de ellas en los últimos 12 meses. 5 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE98
Últimos 12 meses48
Críticas5
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-81383 | Alta (7.4) | 0.92% | — | 8 sept 2026 | Use of incorrectly-resolved name or reference in Visual Studio Code allows an unauthorized attacker to disclose information over a network. |
| CVE-2026-81381 | Alta (7.5) | 0.87% | — | 8 sept 2026 | Insufficiently protected credentials in GitHub Copilot and Visual Studio Code allows an unauthorized attacker to disclose information over a network. |
| CVE-2026-81380 | Media (5.9) | 0.62% | — | 8 sept 2026 | Improper neutralization of special elements used in a command ('command injection') in GitHub Copilot and Visual Studio Code allows an unauthorized attacker to disclose information over a network. |
| CVE-2026-81379 | Alta (8.2) | 0.54% | — | 8 sept 2026 | Not failing securely ('failing open') in Visual Studio Code allows an unauthorized attacker to bypass a security feature over a network. |
| CVE-2026-81378 | Alta (8.2) | 0.54% | — | 8 sept 2026 | Interpretation conflict in Visual Studio Code allows an unauthorized attacker to bypass a security feature over a network. |
| CVE-2026-81377 | Media (6.5) | 0.76% | — | 8 sept 2026 | Improper limitation of a pathname to a restricted directory ('path traversal') in Visual Studio Code allows an unauthorized attacker to perform tampering over a network. |
| CVE-2026-81376 | Crítica (9.6) | 0.82% | — | 8 sept 2026 | Incomplete comparison with missing factors in Visual Studio Code allows an unauthorized attacker to bypass a security feature over a network. |
| CVE-2026-81357 | Alta (8.2) | 0.51% | — | 8 sept 2026 | Server-side request forgery (ssrf) in Visual Studio Code allows an unauthorized attacker to bypass a security feature over a network. |
| CVE-2026-81356 | Alta (8.2) | 0.54% | — | 8 sept 2026 | Inconsistent interpretation of http requests ('http request/response smuggling') in Visual Studio Code allows an unauthorized attacker to bypass a security feature over a network. |
| CVE-2026-78462 | Alta (8.8) | 0.76% | — | 8 sept 2026 | Authorization bypass through user-controlled key in Visual Studio Code allows an unauthorized attacker to bypass a security feature over a network. |
| CVE-2026-78461 | Alta (7.4) | 1.0% | — | 8 sept 2026 | Improper limitation of a pathname to a restricted directory ('path traversal') in Visual Studio Code allows an unauthorized attacker to bypass a security feature over a network. |
| CVE-2026-70334 | Alta (7.8) | 0.47% | — | 8 sept 2026 | Incomplete list of disallowed inputs in Visual Studio Code allows an unauthorized attacker to bypass a security feature locally. |
| CVE-2026-70336 | Alta (8.8) | 0.82% | — | 11 ago 2026 | Improper control of generation of code ('code injection') in Visual Studio Code allows an unauthorized attacker to execute code over a network. |
| CVE-2026-70335 | Alta (7.8) | 0.46% | — | 11 ago 2026 | Improper neutralization of special elements used in an os command ('os command injection') in GitHub Copilot and Visual Studio Code allows an unauthorized attacker to elevate privileges locally. |
| CVE-2026-69320 | Alta (8.8) | 0.86% | — | 11 ago 2026 | Improper neutralization of special elements used in an os command ('os command injection') in Visual Studio Code allows an unauthorized attacker to execute code over a network. |
| CVE-2026-69306 | Alta (8.2) | 0.54% | — | 11 ago 2026 | Not failing securely ('failing open') in Visual Studio Code allows an unauthorized attacker to bypass a security feature over a network. |
| CVE-2026-69278 | Alta (7.8) | 0.32% | — | 11 ago 2026 | Incorrect authorization in Visual Studio Code allows an unauthorized attacker to bypass a security feature locally. |
| CVE-2026-59113 | Alta (8.8) | 0.76% | — | 11 ago 2026 | Missing authorization in Visual Studio Code allows an unauthorized attacker to execute code over a network. |
| CVE-2026-58650 | Alta (7.8) | 0.32% | — | 11 ago 2026 | Authorization bypass through user-controlled key in Visual Studio Code allows an unauthorized attacker to bypass a security feature locally. |
| CVE-2026-47285 | Media (6.5) | 0.92% | — | 11 ago 2026 | Improper neutralization of special elements used in a command ('command injection') in Visual Studio Code allows an unauthorized attacker to disclose information over a network. |
| CVE-2026-48122 | Media (5.4) | 0.18% | — | 7 ago 2026 | Ruby LSP is an implementation of the language server protocol for Ruby. Several workspace-level settings in the Ruby LSP VS Code extension prior to version 0.10.4 could override the path to the Ruby executable, the… |
| CVE-2026-44191 | Alta (7.8) | 0.82% | — | 22 jul 2026 | A flaw was found in the Visual Studio Code Ansible Lightspeed extension. This command injection vulnerability (CWE-78) arises from improper handling of the ansible.executionEnvironment.containerOptions and… |
| CVE-2026-44190 | Alta (7.8) | 0.75% | — | 22 jul 2026 | A flaw was found in the Ansible Lightspeed Visual Studio Code extension. This Command Injection vulnerability (CWE-78) allows a remote attacker to execute unauthorized commands on a user's system. The issue occurs… |
| CVE-2026-44189 | Alta (7.8) | 0.95% | — | 22 jul 2026 | A flaw was found in the Visual Studio Code Ansible Lightspeed extension's AnsiblePlaybookRunProvider. This command injection vulnerability allows an attacker to craft a malicious playbook filename containing special… |
| CVE-2026-44187 | Baja (3.3) | 0.13% | — | 22 jul 2026 | A flaw was found in the Ansible Lightspeed extension for Visual Studio Code. This vulnerability allows an attacker with local access to the workstation, or malware running with the user's privileges, to read the Google… |
| CVE-2026-57102 | Alta (8.8) | 0.82% | — | 14 jul 2026 | Inclusion of functionality from untrusted control sphere in Visual Studio Code allows an unauthorized attacker to bypass a security feature over a network. |
| CVE-2026-57101 | Media (6.1) | 0.48% | — | 14 jul 2026 | Improper neutralization of input during web page generation ('cross-site scripting') in Visual Studio Code allows an unauthorized attacker to bypass a security feature locally. |
| CVE-2026-50520 | Alta (8.4) | 0.35% | — | 14 jul 2026 | Improper neutralization of special elements used in a command ('command injection') in Visual Studio Code allows an unauthorized attacker to execute code locally. |
| CVE-2026-47282 | Media (6.5) | 0.87% | — | 14 jul 2026 | Insufficiently protected credentials in GitHub Copilot and Visual Studio Code allows an unauthorized attacker to disclose information over a network. |
| CVE-2026-45496 | Media (5.5) | 0.47% | — | 14 jul 2026 | Improper limitation of a pathname to a restricted directory ('path traversal') in Visual Studio Code allows an unauthorized attacker to bypass a security feature locally. |