Input validation error in Visual Studio Code - CVE-2026-47281
Published: June 10, 2026 / Updated: July 25, 2026
Vulnerability details
The vulnerability allows a remote attacker to escalate privileges on the target system.
The vulnerability exists due to insufficient validation of user-supplied input in Visual Studio Code. A remote attacker can trick a victim to open a specially crafted code-workspace file and gain elevated privileges on the system.