Junglewise Threat Intelligence

CVE-2026-81357: Microsoft Visual Studio Code server-side request forgery

CVE-2026-81357 · Severity: high · CVSS 8.2 · Published 2026-09-08

Executive brief

Visual Studio Code is a widely-used code editor that developers rely on for building software applications. A server-side request forgery (SSRF) vulnerability allows an attacker to bypass security restrictions and make unauthorized requests from the editor's environment, potentially leading to access to internal systems, data exfiltration, or service disruption.

Technical details

This vulnerability is a server-side request forgery (SSRF) flaw in Visual Studio Code that allows an unauthenticated attacker to bypass security controls over the network. The SSRF vulnerability enables an attacker to craft requests that appear to originate from the victim's editor instance, potentially allowing access to internal resources, metadata endpoints, or other protected services that trust requests from the local environment. The vulnerability is reachable over a network, making it accessible to remote attackers without requiring local access or prior authentication.

Affected products

  • Microsoft Visual Studio Code

Timeline

  • 2026-09-08: disclosed

References

Related threats