Junglewise Threat Intelligence

CVE-2026-57102: Microsoft Visual Studio Code security feature bypass

CVE-2026-57102 · Severity: high · CVSS 8.8 · Published 2026-07-14

Technologies: Microsoft Visual Studio Code. Vendors: Microsoft.

Executive brief

Microsoft Visual Studio Code, a widely used code editor for software development, contains a security vulnerability that could allow an attacker to bypass built-in security protections. By tricking a user into interacting with malicious content, an attacker could potentially gain unauthorized access to sensitive information or execute unauthorized actions. This could lead to the theft of source code, credentials, or a full compromise of the developer's workstation.

Technical details

A vulnerability exists in Microsoft Visual Studio Code due to the inclusion of functionality from an untrusted control sphere (CWE-829). The flaw allows a remote, unauthenticated attacker to bypass security features by leveraging a network-based attack vector. Exploitation requires user interaction, typically involving a user opening a malicious file or visiting a crafted link. Successful exploitation can lead to a total loss of confidentiality, integrity, and availability. Microsoft has addressed this issue in version 1.128.1.

Affected products

  • Microsoft Visual Studio Code 1.0.0 to 1.128.1

Timeline

  • 2026-07-14: advisory: Initial disclosure by Microsoft and NVD.

References

Related threats