Microsoft Visual Studio Code
cpe:2.3:a:microsoft:visual_studio_code:*:*:*:*:*:*:*, +6 more
A cross-site scripting vulnerability has been identified in Visual Studio Code, specifically in the input handling during web page generation. This flaw allows an unauthorized attacker to locally bypass a security feature. The issue affects Visual Studio Code version 1.119.1.
Exploitation of this vulnerability can lead to a security feature bypass, allowing unauthorized actions or access that should be restricted.
To reproduce this vulnerability, a user must open or view a maliciously crafted notebook that contains the affected content. The vulnerability is triggered when the notebook is rendered, allowing the cross-site scripting attack to occur.
Users are advised to update to the latest version of Visual Studio Code. The security update can be downloaded from the Visual Studio Code website.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.