Incomplete Comparison with Missing Factors in Visual Studio Code - CVE-2026-81376

 

Incomplete Comparison with Missing Factors in Visual Studio Code - CVE-2026-81376

Published: September 9, 2026


Vulnerability identifier: #VU148271
CSH Severity: High
CVSS v4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-81376
CWE-ID: CWE-1023
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to access local data or execute code in the context of the user.

The vulnerability exists due to incomplete comparison with missing factors in the Visual Studio Code Workspace Trust feature when opening a specially crafted workspace. A remote attacker can convince a user to open a specially crafted Visual Studio Code workspace to access local data or execute code in the context of the user.

The user does not need to trust the workspace.


Affected software

Visual Studio Code

How to mitigate CVE-2026-81376

Install security update from vendor's website.

Visual Studio Code - update to 1.136.2

External References

Related Security Bulletins