Incomplete List of Disallowed Inputs in Visual Studio Code - CVE-2026-70334
Published: September 9, 2026
Vulnerability details
The vulnerability allows a remote attacker to bypass the Workspace Trust security feature.
The vulnerability exists due to an incomplete list of disallowed inputs in Visual Studio Code when opening an untrusted workspace. A remote attacker can use an input omitted from the disallowed list to bypass the Workspace Trust security feature.
User interaction is required to open the untrusted workspace.