Path traversal in Visual Studio Code - CVE-2026-78461
Published: September 9, 2026
Vulnerability details
The vulnerability allows a remote attacker to bypass the Workspace Trust security feature.
The vulnerability exists due to improper limitation of a pathname to a restricted directory (path traversal) in Visual Studio Code when handling a crafted pathname. A remote attacker can use path traversal to bypass the Workspace Trust security feature.
User interaction is required.