Image

Visual Studio Code — Known Vulnerabilities

56 vulnerabilities mapped against this product across all versions. Grouped by the release each fix landed in — newest tracked release v56.
Still affects the latest release (v56) 16
CVE-2024-43488 Affects current release CVSS 9.8 · Critical NVD ↗ Oct 8, 2024
Missing authentication for critical function in Visual Studio Code extension for Arduino allows an unauthenticated attacker to perform remote code execution through network attack vector.
CVE-2022-21991 Affects current release CVSS 8.1 · High NVD ↗ Feb 9, 2022
Visual Studio Code Remote Development Extension Remote Code Execution Vulnerability
CVE-2021-27060 Affects current release CVSS 7.8 · High NVD ↗ Mar 11, 2021
Visual Studio Code Remote Code Execution Vulnerability
CVE-2020-17148 Fixed in 0.61.0 CVSS 7.8 · High NVD ↗ Dec 10, 2020
Visual Studio Code Remote Development Extension Remote Code Execution Vulnerability
CVE-2020-17104 Affects current release CVSS 7.8 · High NVD ↗ Nov 11, 2020
Visual Studio Code JSHint Extension Remote Code Execution Vulnerability
CVE-2020-17023 Affects current release CVSS 7.8 · High NVD ↗ Oct 16, 2020
A remote code execution vulnerability exists in Visual Studio Code when a user is tricked into opening a malicious 'package.json' file. An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the current…
CVE-2020-0604 Fixed in 0.24.0 CVSS 7.8 · High NVD ↗ Aug 17, 2020
A remote code execution vulnerability exists in Visual Studio Code when it process environment variables after opening a project. An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the current user. If…
CVE-2019-0728 Affects current release CVSS 7.8 · High NVD ↗ Mar 5, 2019
A remote code execution vulnerability exists in Visual Studio Code when it process environment variables after opening a project, aka 'Visual Studio Code Remote Code Execution Vulnerability'.
CVE-2018-0597 Affects current release CVSS 7.8 · High NVD ↗ Jun 26, 2018
Untrusted search path vulnerability in the installer of Visual Studio Code allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.
CVE-2022-41042 Affects current release CVSS 7.4 · High NVD ↗ Oct 11, 2022
Visual Studio Code Information Disclosure Vulnerability
CVE-2022-38020 Affects current release CVSS 7.3 · High NVD ↗ Sep 13, 2022
Visual Studio Code Elevation of Privilege Vulnerability
CVE-2022-26921 Affects current release CVSS 7.3 · High NVD ↗ Apr 15, 2022
Visual Studio Code Elevation of Privilege Vulnerability
CVE-2021-1639 Affects current release CVSS 7.0 · High NVD ↗ Feb 25, 2021
Visual Studio Code Remote Code Execution Vulnerability
CVE-2020-16977 Affects current release CVSS 7.0 · High NVD ↗ Oct 16, 2020
A remote code execution vulnerability exists in Visual Studio Code when the Python extension loads a Jupyter notebook file. An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the current user. If…
CVE-2021-26437 Affects current release CVSS 5.5 · Medium NVD ↗ Sep 15, 2021
Visual Studio Code Spoofing Vulnerability
CVE-2021-43908 Affects current release CVSS 4.3 · Medium NVD ↗ Dec 15, 2021
Visual Studio Code Spoofing Vulnerability
Fixed in v1.x 40
CVE-2025-55319 Fixed in 1.104.0 CVSS 9.8 · Critical NVD ↗ Sep 12, 2025
Ai command injection in Agentic AI and Visual Studio Code allows an unauthorized attacker to execute code over a network.
CVE-2026-41613 Fixed in 1.119.1 CVSS 8.8 · High NVD ↗ May 12, 2026
Session fixation in Visual Studio Code allows an unauthorized attacker to elevate privileges over a network.
CVE-2026-41109 Fixed in 1.119.1 CVSS 8.8 · High NVD ↗ May 12, 2026
Improper neutralization of special elements in output used by a downstream component ('injection') in GitHub Copilot and Visual Studio allows an unauthorized attacker to bypass a security feature over a network.
CVE-2026-21518 Fixed in 1.109.2 CVSS 8.8 · High NVD ↗ Feb 10, 2026
Improper neutralization of special elements used in a command ('command injection') in GitHub Copilot and Visual Studio Code allows an unauthorized attacker to bypass a security feature over a network.
CVE-2024-26165 Fixed in 1.87.2 CVSS 8.8 · High NVD ↗ Mar 12, 2024
Visual Studio Code Elevation of Privilege Vulnerability
CVE-2022-30129 Fixed in 1.67.1 CVSS 8.8 · High NVD ↗ May 10, 2022
Visual Studio Code Remote Code Execution Vulnerability
CVE-2020-1416 Fixed in 1.47.1 CVSS 8.8 · High NVD ↗ Jul 14, 2020
An elevation of privilege vulnerability exists in Visual Studio and Visual Studio Code when they load software dependencies, aka 'Visual Studio and Visual Studio Code Elevation of Privilege Vulnerability'.
CVE-2026-21523 Fixed in 1.109.2 CVSS 8.0 · High NVD ↗ Feb 10, 2026
Time-of-check time-of-use (toctou) race condition in GitHub Copilot and Visual Studio allows an authorized attacker to execute code over a network.
CVE-2025-64660 Fixed in 1.106.2 CVSS 8.0 · High NVD ↗ Nov 20, 2025
Improper access control in GitHub Copilot and Visual Studio Code allows an authorized attacker to execute code over a network.
CVE-2024-43601 Fixed in 1.94.1 CVSS 7.8 · High NVD ↗ Oct 8, 2024
Visual Studio Code for Linux Remote Code Execution Vulnerability
CVE-2023-36742 Fixed in 1.82.1 CVSS 7.8 · High NVD ↗ Sep 12, 2023
Visual Studio Code Remote Code Execution Vulnerability
CVE-2023-24893 Fixed in 1.77.0 CVSS 7.8 · High NVD ↗ Apr 11, 2023
Visual Studio Code Remote Code Execution Vulnerability
CVE-2023-21779 Fixed in 1.74.3 CVSS 7.8 · High NVD ↗ Jan 10, 2023
Visual Studio Code Remote Code Execution Vulnerability
CVE-2022-41034 Fixed in 1.72.1 CVSS 7.8 · High NVD ↗ Oct 11, 2022
Visual Studio Code Remote Code Execution Vulnerability
CVE-2021-43891 Fixed in 1.63.2 CVSS 7.8 · High NVD ↗ Dec 15, 2021
Visual Studio Code Remote Code Execution Vulnerability
CVE-2021-42322 Fixed in 1.16.2 CVSS 7.8 · High NVD ↗ Nov 10, 2021
Visual Studio Code Elevation of Privilege Vulnerability
CVE-2021-34528 Fixed in 1.58.1 CVSS 7.8 · High NVD ↗ Jul 14, 2021
Visual Studio Code Remote Code Execution Vulnerability
CVE-2021-34529 Fixed in 1.57.1 CVSS 7.8 · High NVD ↗ Jul 14, 2021
Visual Studio Code Remote Code Execution Vulnerability
CVE-2021-34479 Fixed in 1.58.1 CVSS 7.8 · High NVD ↗ Jul 14, 2021
Microsoft Visual Studio Spoofing Vulnerability
CVE-2021-31211 Fixed in 1.56.1 CVSS 7.8 · High NVD ↗ May 11, 2021
Visual Studio Code Remote Code Execution Vulnerability
CVE-2021-31214 Fixed in 1.56.1 CVSS 7.8 · High NVD ↗ May 11, 2021
Visual Studio Code Remote Code Execution Vulnerability
CVE-2021-28471 Fixed in 1.55.2 CVSS 7.8 · High NVD ↗ Apr 13, 2021
Remote Development Extension for Visual Studio Code Remote Code Execution Vulnerability
CVE-2021-28473 Fixed in 1.55.2 CVSS 7.8 · High NVD ↗ Apr 13, 2021
Visual Studio Code Remote Code Execution Vulnerability
CVE-2021-28475 Fixed in 1.55.2 CVSS 7.8 · High NVD ↗ Apr 13, 2021
Visual Studio Code Remote Code Execution Vulnerability
CVE-2021-28457 Fixed in 1.55.2 CVSS 7.8 · High NVD ↗ Apr 13, 2021
Visual Studio Code Remote Code Execution Vulnerability
CVE-2021-28469 Fixed in 1.55.2 CVSS 7.8 · High NVD ↗ Apr 13, 2021
Visual Studio Code Remote Code Execution Vulnerability
CVE-2020-16881 Fixed in 1.48.1 CVSS 7.8 · High NVD ↗ Sep 11, 2020
A remote code execution vulnerability exists in Visual Studio Code when a user is tricked into opening a malicious 'package.json' file. An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the current…
CVE-2019-1414 Fixed in 1.39 CVSS 7.8 · High NVD ↗ Jan 24, 2020
An elevation of privilege vulnerability exists in Visual Studio Code when it exposes a debug listener to users of a local computer, aka 'Visual Studio Code Elevation of Privilege Vulnerability'.
CVE-2025-26631 Fixed in 1.98.0 CVSS 7.3 · High NVD ↗ Mar 11, 2025
Uncontrolled search path element in Visual Studio Code allows an authorized attacker to elevate privileges locally.
CVE-2025-24042 Fixed in 1.97.1 CVSS 7.3 · High NVD ↗ Feb 11, 2025
Visual Studio Code JS Debug Extension Elevation of Privilege Vulnerability
CVE-2025-24039 Fixed in 1.97.1 CVSS 7.3 · High NVD ↗ Feb 11, 2025
Visual Studio Code Elevation of Privilege Vulnerability
CVE-2025-21264 Fixed in 1.100.1 CVSS 7.1 · High NVD ↗ May 13, 2025
Files or directories accessible to external parties in Visual Studio Code allows an unauthorized attacker to bypass a security feature locally.
CVE-2021-28477 Fixed in 1.55.2 CVSS 7.0 · High NVD ↗ Apr 13, 2021
Visual Studio Code Remote Code Execution Vulnerability
CVE-2025-32726 Fixed in 1.99.1 CVSS 6.8 · Medium NVD ↗ Apr 12, 2025
Improper access control in Visual Studio Code allows an authorized attacker to elevate privileges locally.
CVE-2023-33144 Fixed in 1.79 CVSS 6.6 · Medium NVD ↗ Jun 14, 2023
Visual Studio Code Spoofing Vulnerability
CVE-2023-29338 Fixed in 1.78.1 CVSS 6.6 · Medium NVD ↗ May 9, 2023
Visual Studio Code Spoofing Vulnerability
CVE-2022-24526 Fixed in 1.65.2 CVSS 6.1 · Medium NVD ↗ Mar 9, 2022
Visual Studio Code Spoofing Vulnerability
CVE-2026-41610 Fixed in 1.119.1 CVSS 5.0 · Medium NVD ↗ May 12, 2026
Improper neutralization of input during web page generation ('cross-site scripting') in Visual Studio Code allows an unauthorized attacker to bypass a security feature locally.
CVE-2025-62453 Fixed in 1.105.0 CVSS 5.0 · Medium NVD ↗ Nov 11, 2025
Improper validation of generative ai output in GitHub Copilot and Visual Studio Code allows an authorized attacker to bypass a security feature locally.
CVE-2026-41611 Fixed in 1.119.1 CVSS 3.3 · Low NVD ↗ May 12, 2026
Improper neutralization of script-related html tags in a web page (basic xss) in Visual Studio Code allows an unauthorized attacker to execute code locally.
Source: NVD · CISA KEV · data as of Jun 8, 2026