Command Injection Vulnerability in Visual Studio Code by Microsoft
CVE-2026-47285

6.5MEDIUM

Key Information:

Vendor

Microsoft

Vendor
CVE Published:
11 August 2026

What is CVE-2026-47285?

A command injection vulnerability exists in Visual Studio Code, allowing an unauthorized attacker to potentially disclose sensitive information over a network. The vulnerability arises due to improper neutralization of special elements used in command execution. This flaw could be exploited by attackers to execute arbitrary commands, leading to information leakage. Users are strongly encouraged to patch their systems to mitigate the risks associated with this flaw.

Affected Version(s)

Visual Studio Code 1.0.0 < 1.132.1

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.