Server-Side Request Forgery Vulnerability in Visual Studio Code by Microsoft
CVE-2026-81357

8.2HIGH

Key Information:

Vendor

Microsoft

Vendor
CVE Published:
8 September 2026

What is CVE-2026-81357?

A server-side request forgery (SSRF) vulnerability exists in Visual Studio Code that enables attackers to exploit network interactions and bypass security features. By leveraging this flaw, an unauthorized user could send crafted requests to vulnerable endpoints, allowing them to gain illicit access to internal resources. This vulnerability underscores the necessity for effective network security measures and vigilance in implementing software updates to safeguard against potential breaches.

Affected Version(s)

Visual Studio Code 1.0.0 < 1.136.2

References

CVSS V3.1

Score:
8.2
Severity:
HIGH
Confidentiality:
High
Integrity:
Low
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.