Visual Studio Code Cross-Site Scripting Vulnerability Allowing Security Feature Bypass

Vulnerability

A cross-site scripting vulnerability has been identified in Visual Studio Code, specifically in the input handling during web page generation. This flaw allows an unauthorized attacker to locally bypass a security feature. The issue affects Visual Studio Code version 1.119.1.

Impact

Exploitation of this vulnerability can lead to a security feature bypass, allowing unauthorized actions or access that should be restricted.

Reproduction

To reproduce this vulnerability, a user must open or view a maliciously crafted notebook that contains the affected content. The vulnerability is triggered when the notebook is rendered, allowing the cross-site scripting attack to occur.

Remediation

Users are advised to update to the latest version of Visual Studio Code. The security update can be downloaded from the Visual Studio Code website.

Added: May 12, 2026, 7:17 PM
Updated: May 12, 2026, 7:17 PM

Vulnerability Rating

Custom Algorithm
spread
6.6
impact
3.1
exploitability
4.6
remediation
7.7
relevance
8.1
threat
1.6
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.