Description
Server-side request forgery (ssrf) in Visual Studio Code allows an unauthorized attacker to bypass a security feature over a network.
Published: 2026-09-08
Score: 8.2 High
EPSS: < 1% Very Low
KEV: No
Impact: Security feature bypass through server-side request forgery
Action: Immediate Patch
AI Analysis

Impact

The vulnerability is a server-side request forgery that permits an attacker to send arbitrary network requests from within Visual Studio Code, thereby bypassing a built-in security restriction. Because the attacker can instruct the application to reach internal or otherwise protected resources, this weakness can lead to unauthorized disclosure or modification of sensitive data and potentially compromise the system in which VS Code is running.

Affected Systems

Microsoft Visual Studio Code, all releases where the vulnerability is present. No specific version details are supplied, indicating that the flaw may exist across multiple or all current versions.

Risk and Exploitability

The flaw carries a CVSS score of 8.2, classifying it as high severity. The EPSS score is not available, and the vulnerability has not been added to CISA’s KEV catalog. Attackers can exploit the weakness by composing an SSRF payload that targets internal services, and the lack of any explicit prerequisite suggests that the attack vector is network-based and could be executed from a remotely connected client or extension.

Generated by OpenCVE AI on September 9, 2026 at 04:07 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Visual Studio Code to the latest version available from Microsoft, which includes the security fix for the SSRF issue.
  • If an upgrade cannot be performed immediately, constrain extension network access by disabling extensions that send external requests or by configuring VS Code to operate in a restricted workspace trust mode.
  • Enforce network‑level controls such as a firewall or proxy to block outbound connections originating from the VS Code process to internal or sensitive IP ranges.
  • Consider running VS Code within a sandboxed container or virtualized environment that limits outbound network traffic.

Generated by OpenCVE AI on September 9, 2026 at 04:07 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 11 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:microsoft:visual_studio_code:*:*:*:*:*:-:*:*

Wed, 09 Sep 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 08 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Description Server-side request forgery (ssrf) in Visual Studio Code allows an unauthorized attacker to bypass a security feature over a network.
Title Visual Studio Code Security Feature Bypass Vulnerability
First Time appeared Microsoft
Microsoft visual Studio Code
Weaknesses CWE-918
CPEs cpe:2.3:a:microsoft:visual_studio_code:*:*:*:*:*:*:*:*
Vendors & Products Microsoft
Microsoft visual Studio Code
References
Metrics cvssV3_1

{'score': 8.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N/E:U/RL:O/RC:C'}


Subscriptions

Microsoft Visual Studio Code
cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-09-25T21:33:51.207Z

Reserved: 2026-08-26T18:40:19.856Z

Link: CVE-2026-81357

cve-icon Vulnrichment

Updated: 2026-09-09T18:57:19.441Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-08T18:20:53.693

Modified: 2026-09-11T21:10:10.457

Link: CVE-2026-81357

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-10T03:15:16Z

Weaknesses
  • CWE-918

    Server-Side Request Forgery (SSRF)