Impact
The vulnerability originates from inconsistent handling of HTTP requests in Visual Studio Code, producing a request/response smuggling scenario that can be exploited by an attacker to bypass a security feature over a network. This flaw, classified as CWE‑444, allows unauthorized users to evade controls that are otherwise intended to enforce request integrity, potentially granting them unrestricted access to data or execution paths within the application.
Affected Systems
Microsoft’s Visual Studio Code is the affected product. No specific version range is listed, implying that all current releases are potentially impacted until the Microsoft security update is applied.
Risk and Exploitability
The risk is high, with a CVSS score of 8.2, and the EPSS score is not available. Because the flaw can be triggered remotely via crafted HTTP traffic, the attack vector is likely network-based. Although no public exploit has yet been documented, the severity rating and known bypass nature suggest that a determined attacker could leverage the weakness to gain unauthorized access where no proper boundary checks exist.
OpenCVE Enrichment