CVE-2026-81383: Visual Studio Code Information Disclosure Vulnerability

Overview

Severity
High (CVSS 7.4)
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:N/A:N/E:U/RL:O/RC:C
Category
Information Disclosure
Exploit Status
Not Exploited
Exploitation Likelihood
Less Likely
Patch Tuesday
2026-Sep
Released
2026-09-08

Description

Use of incorrectly-resolved name or reference in Visual Studio Code allows an unauthorized attacker to disclose information over a network.

FAQ

What type of information could be disclosed by this vulnerability? The type of information that could be disclosed if an attacker successfully exploited this vulnerability is file content. The scope of file content which could be accessed is dependent on the privileges of compromised user.

Affected Products (1)

Developer Tools

  • Visual Studio Code

Security Updates (1)

Acknowledgments

<a href="https://www.linkedin.com/in/marcelkarlsson/">Marcel L. Karlsson (whoismarcel)</a>, Povcfe, Wang Wenshuo, Dong Shuaike

Revision History

  • 2026-09-08: Information published.