Visual Studio Code Security Feature Bypass Vulnerability
CVE-2026-81379
Improper neutralization of special elements used in an os command ('os command injection') in Visual Studio Code allows an unauthorized attacker to execute code over a network.
Release Notes
Review the complete instructions on the vendor's siteSecurityAlert records field-level changes from the point we begin following a bulletin. Earlier vendor changes may not have a field-by-field record.
The publication date reported by the vendor.
We collected the advisory from the official source.
The vendor changed the advisory after it was first published.
Our collector saw this advisory during a later source check.