CVE-2026-54981: Visual Studio Code Python Extension Security Feature Bypass Vulnerability
Overview
- Severity
- High (CVSS 7.8)
- CVSS Vector
- CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
- Category
- Security Feature Bypass
- Exploit Status
- Not Exploited
- Exploitation Likelihood
- Less Likely
- Patch Tuesday
- 2026-Aug
- Released
- 2026-08-11
- Last Updated
- 2026-09-24
- EPSS Score
- 0.47% (percentile: 37.8%)
Description
Inclusion of functionality from untrusted control sphere in Visual Studio Code - Python extension allows an unauthorized attacker to bypass a security feature locally.
FAQ
According to the CVSS metric, the attack vector is local (AV:L) but no privileges are required (PR:N) and user interaction is required (UI:R). How could an attacker exploit this security feature bypass vulnerability?
The attack itself is carried out locally by a user with authentication to the targeted system. An attacker could exploit the vulnerability by convincing a victim, through social engineering, to download and open a specially crafted file from a website which could lead to a local attack on the victim computer.
Affected Products (1)
Developer Tools
- Python extension for Visual Studio Code
Security Updates (1)
Acknowledgments
<a href="https://x.com/zemnmez">Thomas Neil James Shadwell (zemnmez)</a> with <a href="https://openai.com/">OpenAI</a>
Revision History
- 2026-08-11: Information published.
- 2026-08-21: Affected software updated with new package information.
- 2026-09-24: Updated the fixed version information and download link. The fix was previously believed to be included in Dynamics 365 Server (on-premises) version 6.2; however, it has been confirmed that the fix is included in Dynamics 365 Server v9.1 (on-premises) Update 1.45 (version 9.1.0045.0011). The download link, release notes, and build number has been updated accordingly in the Security Updates table. This is an informational change only.