CVE-2026-54981: Visual Studio Code Python Extension Security Feature Bypass Vulnerability

Overview

Severity
High (CVSS 7.8)
CVSS Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
Category
Security Feature Bypass
Exploit Status
Not Exploited
Exploitation Likelihood
Less Likely
Patch Tuesday
2026-Aug
Released
2026-08-11

Description

Inclusion of functionality from untrusted control sphere in Visual Studio Code - Python extension allows an unauthorized attacker to bypass a security feature locally.

FAQ

According to the CVSS metric, the attack vector is local (AV:L) but no privileges are required (PR:N) and user interaction is required (UI:R). How could an attacker exploit this security feature bypass vulnerability? The attack itself is carried out locally by a user with authentication to the targeted system. An attacker could exploit the vulnerability by convincing a victim, through social engineering, to download and open a specially crafted file from a website which could lead to a local attack on the victim computer.

Affected Products (1)

Developer Tools

  • Python extension for Visual Studio Code

Security Updates (1)

Acknowledgments

<a href="https://x.com/zemnmez">Thomas Neil James Shadwell (zemnmez)</a> with <a href="https://openai.com/">OpenAI</a>

Revision History

  • 2026-08-11: Information published.