Impact
Improper neutralization of user input during web page generation in Visual Studio Code creates a cross‑site scripting flaw, allowing an attacker to inject malicious code that bypasses built‑in security controls. CWE‑79, and it can be used to execute arbitrary scripts within the application’s context, potentially modifying the local environment. The violation of confidentiality and integrity is limited to the installer’s user or local user who can craft files or URLs that the editor processes.
Affected Systems
Microsoft Visual Studio Code is affected; the specific affected versions are not detailed in the current data, indicating that the vulnerability may exist in any installation of VS Code that has not applied the vendor fix. Users should check for the latest update that includes the patch to mitigate the flaw.
Risk and Exploitability
The CVSS score of 7.1 suggests moderate severity, while the EPSS of less than 1 % implies a very low likelihood of exploitation. The flaw is not listed in CISA’s KEV catalog, which further indicates no widely known active exploits. The attack vector is inferred to be local, requiring the attacker to supply or open a malicious file or URL that the editor processes; remote exploitation is not described. Given the moderate score and low exploitation probability, the threat is moderate but not urgent, yet patching remains recommended to eliminate the local bypass risk.
OpenCVE Enrichment