An issue in Visual Studio Code Extensions Live Server v5.7.9 allows attackers to exfiltrate files via user interaction with a crafted HTML page.

Subscriptions

Vendors Products
Ritwickdey Subscribe
Live Server Subscribe
Vscode-live-server Subscribe

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Wed, 25 Feb 2026 18:45:00 +0000

Type Values Removed Values Added
First Time appeared Ritwickdey live Server
CPEs cpe:2.3:a:ritwickdey:live_server:*:*:*:*:*:visual_studio_code:*:*
Vendors & Products Ritwickdey live Server

Wed, 18 Feb 2026 21:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 9.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}

cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 17 Feb 2026 15:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-200
CWE-601
CWE-79
Metrics cvssV3_1

{'score': 9.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 17 Feb 2026 09:00:00 +0000

Type Values Removed Values Added
First Time appeared Ritwickdey
Ritwickdey vscode-live-server
Vendors & Products Ritwickdey
Ritwickdey vscode-live-server

Mon, 16 Feb 2026 15:45:00 +0000

Type Values Removed Values Added
Description An issue in Visual Studio Code Extensions Live Server v5.7.9 allows attackers to exfiltrate files via user interaction with a crafted HTML page.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-02-18T20:30:35.580Z

Reserved: 2025-11-18T00:00:00.000Z

Link: CVE-2025-65717

cve-icon Vulnrichment

Updated: 2026-02-17T15:00:34.448Z

cve-icon NVD

Status : Analyzed

Published: 2026-02-16T16:19:17.510

Modified: 2026-02-25T18:43:19.847

Link: CVE-2025-65717

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-02-17T08:56:21Z

Weaknesses