Visual Studio Code
Products
10- 6 CVEs
- 1 CVE
- 1 CVE
- 1 CVE
- 1 CVE
- 1 CVE
- 1 CVE
- 1 CVE
- 1 CVE
- 1 CVE
Recent CVEs
15| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2022-30129 | Hig | 0.54 | 8.8 | 0.42 | May 10, 2022 | Visual Studio Code Remote Code Execution Vulnerability | ||
| CVE-2021-28953 | Hig | 0.51 | 7.8 | 0.01 | Mar 21, 2021 | The unofficial C/C++ Advanced Lint extension before 1.9.0 for Visual Studio Code allows attackers to execute arbitrary binaries if the user opens a crafted repository. | ||
| CVE-2021-28790 | Hig | 0.51 | 7.8 | 0.02 | Mar 18, 2021 | The unofficial SwiftLint extension before 1.4.5 for Visual Studio Code allows remote attackers to execute arbitrary code by constructing a malicious workspace with a crafted swiftlint.path configuration value that triggers execution upon opening the workspace. | ||
| CVE-2021-28789 | Hig | 0.51 | 7.8 | 0.02 | Mar 18, 2021 | The unofficial apple/swift-format extension before 1.1.2 for Visual Studio Code allows remote attackers to execute arbitrary code by constructing a malicious workspace with a crafted apple-swift-format.path configuration value that triggers execution upon opening the workspace. | ||
| CVE-2021-21420 | Hig | 0.49 | 7.5 | 0.01 | Apr 1, 2021 | vscode-stripe is an extension for Visual Studio Code. A vulnerability in Stripe for Visual Studio Code extension exists when it loads an untrusted source-code repository containing malicious settings. An attacker who successfully exploited the vulnerability could run arbitrary… | ||
| CVE-2026-41610 | Med | 0.41 | 6.3 | 0.01 | May 12, 2026 | Improper neutralization of input during web page generation ('cross-site scripting') in Visual Studio Code allows an unauthorized attacker to bypass a security feature locally. | ||
| CVE-2026-41612 | Med | 0.36 | 5.5 | 0.01 | May 12, 2026 | Relative path traversal in Visual Studio Code allows an unauthorized attacker to disclose information locally. | ||
| CVE-2025-65715 | 0.00 | — | 0.00 | Feb 16, 2026 | An issue in the code-runner.executorMap setting of Visual Studio Code Extensions Code Runner v0.12.2 allows attackers to execute arbitrary code when opening a crafted workspace. | |||
| CVE-2021-30124 | Cri | 0.00 | 9.8 | 0.03 | Jul 30, 2021 | The unofficial vscode-phpmd (aka PHP Mess Detector) extension before 1.3.0 for Visual Studio Code allows remote attackers to execute arbitrary code via a crafted phpmd.command value in a workspace folder. | ||
| CVE-2021-30502 | Cri | 0.00 | 9.8 | 0.03 | Apr 25, 2021 | The unofficial vscode-ghc-simple (aka Simple Glasgow Haskell Compiler) extension before 0.2.3 for Visual Studio Code allows remote code execution via a crafted workspace configuration with replCommand. | ||
| CVE-2021-31414 | Cri | 0.00 | 9.8 | 0.02 | Apr 16, 2021 | The unofficial vscode-rpm-spec extension before 0.3.2 for Visual Studio Code allows remote code execution via a crafted workspace configuration. | ||
| CVE-2021-30503 | Cri | 0.00 | 9.8 | 0.03 | Apr 13, 2021 | The unofficial GLSL Linting extension before 1.4.0 for Visual Studio Code allows remote code execution via a crafted glslangValidatorPath in the workspace configuration. | ||
| CVE-2021-29658 | Hig | 0.00 | 8.8 | 0.01 | Mar 31, 2021 | The unofficial vscode-rufo extension before 0.0.4 for Visual Studio Code allows attackers to execute arbitrary binaries if the user opens a crafted workspace folder. | ||
| CVE-2021-28967 | Cri | 0.00 | 9.8 | 0.02 | Mar 24, 2021 | The unofficial MATLAB extension before 2.0.1 for Visual Studio Code allows attackers to execute arbitrary code via a crafted workspace because of lint configuration settings. | ||
| CVE-2021-28794 | Cri | 0.00 | 9.8 | 0.02 | Mar 18, 2021 | The unofficial ShellCheck extension before 0.13.4 for Visual Studio Code mishandles shellcheck.executablePath. |
- risk 0.54cvss 8.8epss 0.42
Visual Studio Code Remote Code Execution Vulnerability
- risk 0.51cvss 7.8epss 0.01
The unofficial C/C++ Advanced Lint extension before 1.9.0 for Visual Studio Code allows attackers to execute arbitrary binaries if the user opens a crafted repository.
- risk 0.51cvss 7.8epss 0.02
The unofficial SwiftLint extension before 1.4.5 for Visual Studio Code allows remote attackers to execute arbitrary code by constructing a malicious workspace with a crafted swiftlint.path configuration value that triggers execution upon opening the workspace.
- risk 0.51cvss 7.8epss 0.02
The unofficial apple/swift-format extension before 1.1.2 for Visual Studio Code allows remote attackers to execute arbitrary code by constructing a malicious workspace with a crafted apple-swift-format.path configuration value that triggers execution upon opening the workspace.
- risk 0.49cvss 7.5epss 0.01
vscode-stripe is an extension for Visual Studio Code. A vulnerability in Stripe for Visual Studio Code extension exists when it loads an untrusted source-code repository containing malicious settings. An attacker who successfully exploited the vulnerability could run arbitrary…
- risk 0.41cvss 6.3epss 0.01
Improper neutralization of input during web page generation ('cross-site scripting') in Visual Studio Code allows an unauthorized attacker to bypass a security feature locally.
- risk 0.36cvss 5.5epss 0.01
Relative path traversal in Visual Studio Code allows an unauthorized attacker to disclose information locally.
- CVE-2025-65715Feb 16, 2026risk 0.00cvss —epss 0.00
An issue in the code-runner.executorMap setting of Visual Studio Code Extensions Code Runner v0.12.2 allows attackers to execute arbitrary code when opening a crafted workspace.
- risk 0.00cvss 9.8epss 0.03
The unofficial vscode-phpmd (aka PHP Mess Detector) extension before 1.3.0 for Visual Studio Code allows remote attackers to execute arbitrary code via a crafted phpmd.command value in a workspace folder.
- risk 0.00cvss 9.8epss 0.03
The unofficial vscode-ghc-simple (aka Simple Glasgow Haskell Compiler) extension before 0.2.3 for Visual Studio Code allows remote code execution via a crafted workspace configuration with replCommand.
- risk 0.00cvss 9.8epss 0.02
The unofficial vscode-rpm-spec extension before 0.3.2 for Visual Studio Code allows remote code execution via a crafted workspace configuration.
- risk 0.00cvss 9.8epss 0.03
The unofficial GLSL Linting extension before 1.4.0 for Visual Studio Code allows remote code execution via a crafted glslangValidatorPath in the workspace configuration.
- risk 0.00cvss 8.8epss 0.01
The unofficial vscode-rufo extension before 0.0.4 for Visual Studio Code allows attackers to execute arbitrary binaries if the user opens a crafted workspace folder.
- risk 0.00cvss 9.8epss 0.02
The unofficial MATLAB extension before 2.0.1 for Visual Studio Code allows attackers to execute arbitrary code via a crafted workspace because of lint configuration settings.
- risk 0.00cvss 9.8epss 0.02
The unofficial ShellCheck extension before 0.13.4 for Visual Studio Code mishandles shellcheck.executablePath.