Cross-Site Scripting Vulnerability in Visual Studio Code by Microsoft
CVE-2026-41610
6.3MEDIUM
What is CVE-2026-41610?
A cross-site scripting vulnerability exists in Visual Studio Code due to improper input neutralization during web page generation. This flaw enables an unauthorized attacker to bypass local security mechanisms, potentially leading to unauthorized actions or access to sensitive information. Users are advised to update their installations to mitigate risks associated with this vulnerability.
Affected Version(s)
Visual Studio Code 1.0.0 < 1.119.1