Incomplete List of Disallowed Inputs in Visual Studio Code - CVE-2026-70334

 

Incomplete List of Disallowed Inputs in Visual Studio Code - CVE-2026-70334

Published: September 9, 2026


Vulnerability identifier: #VU148031
CSH Severity: High
CVSS v4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-70334
CWE-ID: CWE-184
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to bypass the Workspace Trust security feature.

The vulnerability exists due to an incomplete list of disallowed inputs in Visual Studio Code when opening an untrusted workspace. A remote attacker can use an input omitted from the disallowed list to bypass the Workspace Trust security feature.

User interaction is required to open the untrusted workspace.


Affected software

Visual Studio Code

How to mitigate CVE-2026-70334

Install security update from vendor's website.

Visual Studio Code - update to 1.136.2

External References

Related Security Bulletins