Cross-Site Scripting Vulnerability in Visual Studio Code by Microsoft
CVE-2026-41611
7.8HIGH
What is CVE-2026-41611?
A cross-site scripting (XSS) vulnerability exists in Visual Studio Code, stemming from improper handling of script-related HTML tags. This flaw allows an unauthorized attacker to execute harmful scripts within the context of a user's session, potentially leading to local code execution. It underscores the importance of maintaining up-to-date software and applying security patches promptly to mitigate such risks.
Affected Version(s)
Visual Studio Code 1.0.0 < 1.119.1