Incorrect authorization in Visual Studio Code - CVE-2026-69278
Published: August 12, 2026
Vulnerability details
The vulnerability allows a remote attacker to bypass a security feature.
The vulnerability exists due to incorrect authorization in the Workspace Trust feature when opening an untrusted workspace. A remote attacker can trick the victim into opening an untrusted workspace to bypass a security feature.
Successful exploitation can allow content from an untrusted workspace to run commands or code without the user first granting trust.