Junglewise Threat Intelligence

CVE-2026-69320: Microsoft Visual Studio Code OS command injection

CVE-2026-69320 · Severity: high · CVSS 8.8 · Published 2026-08-11

Technologies: Microsoft Visual Studio Code. Vendors: Microsoft.

Executive brief

Visual Studio Code is a widely-used code editor used by developers across organizations. An OS command injection vulnerability allows a remote attacker to execute arbitrary code on a developer's machine through the network, potentially compromising source code, credentials, and sensitive development environments.

Technical details

The vulnerability is an OS command injection (CWE-78) flaw in Visual Studio Code that fails to properly neutralize special elements in operating system commands. The vulnerability is network-reachable and allows an unauthorized attacker to execute code remotely without requiring prior authentication. An attacker can craft malicious input to inject OS commands that are executed with the privileges of the user running Visual Studio Code, potentially leading to full system compromise.

Affected products

  • Microsoft Visual Studio Code

Timeline

  • 2026-08-11: disclosed

References

Related threats