Interpretation Conflict in Visual Studio Code - CVE-2026-81378
Published: September 9, 2026
Vulnerability details
The vulnerability allows a remote attacker to bypass configured network access restrictions.
The vulnerability exists due to an interpretation conflict in the Visual Studio Code agent when processing attacker-controlled content that causes it to request a specially crafted URL. A remote attacker can influence the processed content to bypass configured network access restrictions.
User interaction is required to run the agent against attacker-controlled content.