Inclusion of Functionality from Untrusted Control Sphere in Python extension for Visual Studio Code - CVE-2026-54981
Published: August 13, 2026
Vulnerability details
The vulnerability allows a remote attacker to gain unauthorized access to otherwise restricted functionality.
The vulnerability exists due to inclusion of functionality from untrusted control sphere in Visual Studio Code Python Extension. A remote attacker can trick a victim to open a specially crafted file and bypass a security feature on the system.