Impact
Visual Studio Code contains an incomplete list of disallowed inputs that allows an attacker with local privileges to bypass a security feature. This flaw is classified as CWE-184 and can enable an attacker to execute or elevate code on the local machine, thereby compromising confidentiality, integrity, or availability of the system. The impact is limited to the local context and requires an authorized attacker with sufficient local privileges to trigger the bypass.
Affected Systems
The affected product is Microsoft Visual Studio Code. No specific affected versions are listed, so all versions may be vulnerable until an official update is released.
Risk and Exploitability
The CVSS score of 7.8 indicates moderate to high severity. Because the EPSS score is not available, the likelihood of exploitation is uncertain, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is local, requiring an attacker to run or inject code into the Visual Studio Code environment, which is usually restricted to authorized users. The risk remains moderate; organizations should consider the vulnerability particularly if they allow users to run untrusted extensions or scripts within VS Code.
OpenCVE Enrichment