Cross-Site Scripting Vulnerability in Visual Studio Code by Microsoft
CVE-2026-41611

7.8HIGH

Key Information:

Vendor

Microsoft

Vendor
CVE Published:
12 May 2026

What is CVE-2026-41611?

A cross-site scripting (XSS) vulnerability exists in Visual Studio Code, stemming from improper handling of script-related HTML tags. This flaw allows an unauthorized attacker to execute harmful scripts within the context of a user's session, potentially leading to local code execution. It underscores the importance of maintaining up-to-date software and applying security patches promptly to mitigate such risks.

Affected Version(s)

Visual Studio Code 1.0.0 < 1.119.1

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.