Authorization bypass through user-controlled key in Visual Studio Code - CVE-2026-58650
Published: August 12, 2026
Vulnerability details
The vulnerability allows a remote attacker to bypass a security feature.
The vulnerability exists due to authorization bypass through user-controlled key in the Workspace Trust feature when processing content from an untrusted workspace. A remote attacker can trick the victim into opening an untrusted workspace to bypass a security feature.
Successful exploitation can allow commands or code from an untrusted workspace to run without the user first granting trust.