Jul 2026: Visual Studio Code Security Feature Bypass Vulnerability
CVE-2026-57102 Published on July 14, 2026

Visual Studio Code Security Feature Bypass Vulnerability
Inclusion of functionality from untrusted control sphere in Visual Studio Code allows an unauthorized attacker to bypass a security feature over a network.

Vendor Advisory NVD

Weakness Types

Inclusion of Functionality from Untrusted Control Sphere

The software imports, requires, or includes executable functionality (such as a library) from a source that is outside of the intended control sphere.

What is an Information Disclosure Vulnerability?

The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

CVE-2026-57102 has been classified to as an Information Disclosure vulnerability or weakness.


Products Associated with CVE-2026-57102

Want to know whenever a new CVE is published for Microsoft Visual Studio Code? stack.watch will email you.

 

Affected Versions

Microsoft Visual Studio Code: