Authorization bypass through user-controlled key in Visual Studio Code - CVE-2026-78462
Published: September 9, 2026
Vulnerability details
The vulnerability allows a remote attacker to bypass Workspace Trust restrictions and execute code in the context of the user.
The vulnerability exists due to authorization bypass through user-controlled key in the Visual Studio Code Workspace Trust feature when opening a specially crafted workspace. A remote attacker can convince a user to open a specially crafted Visual Studio Code workspace to bypass Workspace Trust restrictions and execute code in the context of the user.
User interaction is required, but the user does not need to trust the workspace.