Server-Side Request Forgery (SSRF) in Visual Studio Code - CVE-2026-81357
Published: September 9, 2026
Vulnerability details
The vulnerability allows a remote attacker to bypass network access restrictions.
The vulnerability exists due to server-side request forgery (SSRF) in the Visual Studio Code agent when processing attacker-controlled content that contains a specially crafted URL. A remote attacker can cause the agent to request a specially crafted URL to bypass network access restrictions.
User interaction is required to run the agent against attacker-controlled content.