Visual Studio Code Python Extension Trust Boundary Violation Leading to Remote Code Execution

Vulnerability

A trust boundary violation vulnerability has been identified in the Python extension for Visual Studio Code. This vulnerability allows an unauthorized attacker to execute code locally. It affects version 2025.8.1 of the Python extension.

Impact

Exploitation of this vulnerability could lead to unauthorized local code execution.

Added: Jul 8, 2025, 7:11 PM
Updated: Jul 8, 2025, 7:11 PM

Vulnerability Rating

Custom Algorithm
spread
7.8
impact
10.0
exploitability
4.4
remediation
7.7
relevance
0.2
threat
0.0
urgency
2.9
incentive
0.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.