VYPR

Visual Studio Code

by Microsoft

Source repositories

CVEs (85)

  • CVE-2026-57102HigJul 14, 2026
    risk 0.00cvss 8.8epss 0.01

    Inclusion of functionality from untrusted control sphere in Visual Studio Code allows an unauthorized attacker to bypass a security feature over a network.

  • CVE-2026-57101HigJul 14, 2026
    risk 0.00cvss 7.1epss 0.00

    Improper neutralization of input during web page generation ('cross-site scripting') in Visual Studio Code allows an unauthorized attacker to bypass a security feature locally.

  • CVE-2026-50520HigJul 14, 2026
    risk 0.00cvss 8.4epss 0.00

    Improper neutralization of special elements used in a command ('command injection') in Visual Studio Code allows an unauthorized attacker to execute code locally.

  • CVE-2026-47282MedJul 14, 2026
    risk 0.00cvss 6.5epss 0.01

    Insufficiently protected credentials in GitHub Copilot and Visual Studio Code allows an unauthorized attacker to disclose information over a network.

  • CVE-2026-45496MedJul 14, 2026
    risk 0.00cvss 5.5epss 0.00

    Improper limitation of a pathname to a restricted directory ('path traversal') in Visual Studio Code allows an unauthorized attacker to bypass a security feature locally.

Page 5 of 5