CVE-2026-59113: Visual Studio Code Remote Code Execution Vulnerability
Overview
- Severity
- High (CVSS 8.8)
- CVSS Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
- Category
- Remote Code Execution
- Exploit Status
- Not Exploited
- Exploitation Likelihood
- Less Likely
- Patch Tuesday
- 2026-Aug
- Released
- 2026-08-11
- Last Updated
- 2026-09-24
- EPSS Score
- 0.76% (percentile: 53.3%)
Description
Missing authorization in Visual Studio Code allows an unauthorized attacker to execute code over a network.
FAQ
How could an attacker exploit this vulnerability?
An attacker could host a specially crafted web page and use social engineering to convince a user to have the application retrieve it. The malicious page could then cause the application to launch operating-system protocol handlers without prompting the user, which could result in code execution on the user's system. User interaction is required.
Affected Products (1)
Developer Tools
Security Updates (1)
Acknowledgments
<a href="https://www.linkedin.com/in/sdalili/">Soroush Dalili</a> with <a href="https://www.bentley.com/">Bentley Systems</a>
Revision History
- 2026-08-11: Information published.
- 2026-09-02: Affected software updated with new package information.
- 2026-09-24: Updated the fixed version information and download link. The fix was previously believed to be included in Dynamics 365 Server (on-premises) version 6.2; however, it has been confirmed that the fix is included in Dynamics 365 Server v9.1 (on-premises) Update 1.45 (version 9.1.0045.0011). The download link, release notes, and build number has been updated accordingly in the Security Updates table. This is an informational change only.