Session Fixation Vulnerability in Visual Studio Code by Microsoft
CVE-2026-41613

8.8HIGH

Key Information:

Vendor

Microsoft

Vendor
CVE Published:
12 May 2026

What is CVE-2026-41613?

A session fixation vulnerability in Visual Studio Code allows unauthorized attackers to potentially elevate their privileges over a network, compromising user sessions. This could lead to unauthorized access to sensitive information or the execution of unwanted actions within the application. Users should ensure their software is up to date and follow security best practices to mitigate risks associated with this vulnerability.

Affected Version(s)

Visual Studio Code 1.0.0 < 1.119.1

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.