Authorization bypass through user-controlled key in Visual Studio Code - CVE-2026-78462

 

Authorization bypass through user-controlled key in Visual Studio Code - CVE-2026-78462

Published: September 9, 2026


Vulnerability identifier: #VU148216
CSH Severity: High
CVSS v4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-78462
CWE-ID: CWE-639
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to bypass Workspace Trust restrictions and execute code in the context of the user.

The vulnerability exists due to authorization bypass through user-controlled key in the Visual Studio Code Workspace Trust feature when opening a specially crafted workspace. A remote attacker can convince a user to open a specially crafted Visual Studio Code workspace to bypass Workspace Trust restrictions and execute code in the context of the user.

User interaction is required, but the user does not need to trust the workspace.


Affected software

Visual Studio Code

How to mitigate CVE-2026-78462

Install security update from vendor's website.

Visual Studio Code - update to 1.136.2

External References

Related Security Bulletins