Command Injection Vulnerability in Visual Studio Code by Microsoft
CVE-2026-47285
6.5MEDIUM
What is CVE-2026-47285?
A command injection vulnerability exists in Visual Studio Code, allowing an unauthorized attacker to potentially disclose sensitive information over a network. The vulnerability arises due to improper neutralization of special elements used in command execution. This flaw could be exploited by attackers to execute arbitrary commands, leading to information leakage. Users are strongly encouraged to patch their systems to mitigate the risks associated with this flaw.
Affected Version(s)
Visual Studio Code 1.0.0 < 1.132.1