Microsoft
Microsoft Vscode: vulnerabilidades y CVE
Microsoft Vscode tiene 4 vulnerabilidades publicadas, 2 de ellas en los últimos 12 meses. 0 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE4
Últimos 12 meses2
Críticas0
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-89321 | Media (4.3) | 0.44% | — | 14 sept 2026 | Publishing limits the compressed size of a VSIX (ovsx.publishing.max-content-size, 512 MB by default) but nothing limited how large an entry becomes when opened. On the first request to… |
| CVE-2026-22718 | Media (6.8) | 0.59% | — | 14 ene 2026 | The VSCode extension for Spring CLI are vulnerable to command injection, resulting in command execution on the users machine. |
| CVE-2025-52882 | Alta (8.8) | 0.34% | — | 24 jun 2025 | Claude Code is an agentic coding tool. Claude Code extensions in VSCode and forks (e.g., Cursor, Windsurf, and VSCodium) and JetBrains IDEs (e.g., IntelliJ, Pycharm, and Android Studio) are vulnerable to unauthorized… |
| CVE-2024-56083 | Alta (8.1) | 0.54% | — | 16 dic 2024 | Cognition Devin before 2024-12-12 provides write access to code by an attacker who discovers the https://vscode-randomly_generated_string.devinapps.com URL (aka the VSCode live share URL) for a specific "Use Devin's… |