CVE-2026-47287: Visual Studio Code Tampering Vulnerability
Overview
- Severity
- Medium (CVSS 6.5)
- CVSS Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N/E:U/RL:O/RC:C
- Category
- Tampering
- Exploit Status
- Not Exploited
- Exploitation Likelihood
- Less Likely
- Patch Tuesday
- 2026-Jun
- Released
- 2026-06-09
- EPSS Score
- 0.79% (percentile: 52.4%)
Description
Relative path traversal in Visual Studio Code allows an unauthorized attacker to perform tampering over a network.
FAQ
According to the CVSS metric, user interaction is required (UI:R). What interaction would the user have to do?
The user would have be enticed to open a malicious file in vscode. Users should never open anything that they do not know or trust to be safe.
Affected Products (1)
Developer Tools
Security Updates (1)
Acknowledgments
Ian Brandeberry with <a href="https://msrc.microsoft.com/">Microsoft</a>
Revision History
- 2026-06-09: Information published.