CVE-2026-47281: Visual Studio Code Elevation of Privilege Vulnerability

Overview

Severity
Critical (CVSS 9.6)
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H/E:U/RL:O/RC:C
Category
Elevation of Privilege
Exploit Status
Not Exploited
Exploitation Likelihood
Unlikely
Patch Tuesday
2026-Jun
Released
2026-06-09

Description

Improper input validation in Visual Studio Code allows an unauthorized attacker to elevate privileges over a network.

FAQ

What privileges could be gained by an attacker who successfully exploited this vulnerability? An attacker who successfully exploited this vulnerability could gain SYSTEM privileges. According to the CVSS metric, a successful exploitation could lead to a scope change (S:C). What does this mean for this vulnerability? This means that a successful attack is not limited to Visual Studio Code itself, but can also affect the user’s local system, including files and settings. As a result, the impact extends beyond the application to a different security boundary, increasing the overall severity of the vulnerability. According to the CVSS metric, user interaction is required (UI:R). What interaction would the user have to do? The user would have be enticed to open a malicious .code-workspace file in vscode. Users should never open anything that they do not know or trust to be safe.

Affected Products (1)

Developer Tools

  • Visual Studio Code

Security Updates (1)

Acknowledgments

<a href="https://bsky.app/profile/evilpacket.net">Adam Baldwin</a> with https://evilpacket.net/

Revision History

  • 2026-06-09: Information published.