Executive brief
A vulnerability in the Microsoft Live Share Canvas SDK could allow an authorized user to gain unauthorized privileges during a collaborative session. This SDK is used to build interactive, shared visual experiences in applications like Microsoft Teams. If exploited, an attacker could execute malicious scripts in another user's browser, potentially leading to data theft or unauthorized actions within the application.
Technical details
A stored cross-site scripting (XSS) vulnerability exists in the Microsoft Live Share Canvas SDK due to improper neutralization of input during web page generation. An authenticated attacker with network access can exploit this by injecting malicious scripts into a shared canvas session. Successful exploitation requires a victim to interact with the affected component, allowing the attacker to execute arbitrary code in the context of the victim's browser session and achieve an elevation of privilege. The vulnerability is tracked as CWE-79 and carries a CVSS 3.1 score of 8.0.
Affected products
- Microsoft Live Share Canvas SDK
Timeline
- 2026-06-09: disclosed
- 2026-06-09: advisory