Visual Studio Code Remote Code Execution Vulnerability

Vulnerability

A vulnerability allowing improper neutralization of script-related HTML tags, leading to basic cross-site scripting (XSS), has been identified in Visual Studio Code. This issue allows an unauthorized attacker to execute code locally. The vulnerability affects Visual Studio Code versions prior to 1.119.1.

Impact

Exploitation of this vulnerability could lead to unauthorized local code execution.

Remediation

Users are advised to update to Visual Studio Code version 1.119.1 or later. The security update can be downloaded from the Visual Studio Code website.

Added: May 12, 2026, 7:17 PM
Updated: May 12, 2026, 7:17 PM

Vulnerability Rating

Custom Algorithm
spread
6.6
impact
7.5
exploitability
4.2
remediation
7.7
relevance
8.1
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.