Impact
The vulnerability is a server-side request forgery that permits an attacker to send arbitrary network requests from within Visual Studio Code, thereby bypassing a built-in security restriction. Because the attacker can instruct the application to reach internal or otherwise protected resources, this weakness can lead to unauthorized disclosure or modification of sensitive data and potentially compromise the system in which VS Code is running.
Affected Systems
Microsoft Visual Studio Code, all releases where the vulnerability is present. No specific version details are supplied, indicating that the flaw may exist across multiple or all current versions.
Risk and Exploitability
The flaw carries a CVSS score of 8.2, classifying it as high severity. The EPSS score is not available, and the vulnerability has not been added to CISA’s KEV catalog. Attackers can exploit the weakness by composing an SSRF payload that targets internal services, and the lack of any explicit prerequisite suggests that the attack vector is network-based and could be executed from a remotely connected client or extension.
OpenCVE Enrichment