Not Failing Securely ('Failing Open') in Visual Studio Code - CVE-2026-81379
Published: September 9, 2026
Vulnerability details
The vulnerability allows a remote attacker to bypass configured network access restrictions.
The vulnerability exists due to not failing securely (\'failing open\') in the Visual Studio Code agent when processing attacker-controlled content. A remote attacker can influence content so that the agent requests a specially crafted URL to bypass configured network access restrictions.
User interaction is required to run the agent against attacker-controlled content.