Relative path traversal in Visual Studio Code allows an unauthorized attacker to perform tampering over a network.
According to the CVSS metric, user interaction is required (UI:R). What interaction would the user have to do? The user would have be enticed to open a malicious file in vscode. Users should never open anything that they do not know or trust to be safe.
Ian Brandeberry with <a href="https://msrc.microsoft.com/">Microsoft</a>