Cross-Site Scripting Vulnerability in Visual Studio Code by Microsoft
CVE-2026-41610

6.3MEDIUM

Key Information:

Vendor

Microsoft

Vendor
CVE Published:
12 May 2026

What is CVE-2026-41610?

A cross-site scripting vulnerability exists in Visual Studio Code due to improper input neutralization during web page generation. This flaw enables an unauthorized attacker to bypass local security mechanisms, potentially leading to unauthorized actions or access to sensitive information. Users are advised to update their installations to mitigate risks associated with this vulnerability.

Affected Version(s)

Visual Studio Code 1.0.0 < 1.119.1

References

CVSS V3.1

Score:
6.3
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.