Executive brief
Visual Studio Code, a widely-used code editor, contains a vulnerability in how it resolves names or references that allows an attacker to disclose sensitive information over the network. An unauthorized attacker can exploit this flaw to gain access to confidential data without requiring authentication, potentially exposing source code, credentials, or other sensitive details handled within the editor.
Technical details
The vulnerability involves incorrect name or reference resolution in Visual Studio Code, allowing an information disclosure attack over a network. The flaw permits unauthorized attackers to extract sensitive information without prior authentication. The attack vector is network-based, meaning the attacker can initiate the exploit remotely. While the exact vulnerable component and version range are not fully detailed in available sources, the issue has a CVSS score of 7.4 (high severity) and is not known to be actively exploited in the wild at the time of disclosure.
Affected products
- Microsoft Visual Studio Code
Timeline
- 2026-09-08: disclosed