Microsoft Visual Studio Code
cpe:2.3:a:microsoft:visual_studio_code:*:*:*:*:*:*:*, +6 more
A vulnerability allowing improper neutralization of script-related HTML tags, leading to basic cross-site scripting (XSS), has been identified in Visual Studio Code. This issue allows an unauthorized attacker to execute code locally. The vulnerability affects Visual Studio Code versions prior to 1.119.1.
Exploitation of this vulnerability could lead to unauthorized local code execution.
Users are advised to update to Visual Studio Code version 1.119.1 or later. The security update can be downloaded from the Visual Studio Code website.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.