Path traversal in Visual Studio Code - CVE-2026-81377
Published: September 9, 2026
Vulnerability details
The vulnerability allows a remote attacker to tamper with files.
The vulnerability exists due to improper limitation of a pathname to a restricted directory (path traversal) in Visual Studio Code when handling user-controlled pathnames. A remote attacker can use path traversal to access files outside a restricted directory to tamper with files.
User interaction is required.