Jul 2026: Visual Studio Code Security Feature Bypass Vulnerability
CVE-2026-57102 Published on July 14, 2026
Visual Studio Code Security Feature Bypass Vulnerability
Inclusion of functionality from untrusted control sphere in Visual Studio Code allows an unauthorized attacker to bypass a security feature over a network.
Weakness Types
Inclusion of Functionality from Untrusted Control Sphere
The software imports, requires, or includes executable functionality (such as a library) from a source that is outside of the intended control sphere.
What is an Information Disclosure Vulnerability?
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
CVE-2026-57102 has been classified to as an Information Disclosure vulnerability or weakness.
Products Associated with CVE-2026-57102
Want to know whenever a new CVE is published for Microsoft Visual Studio Code? stack.watch will email you.
Affected Versions
Microsoft Visual Studio Code:- Version 1.0.0 and below 1.128.1 is affected.