Description
Improper limitation of a pathname to a restricted directory ('path traversal') in Visual Studio Code allows an unauthorized attacker to perform tampering over a network.
Published: 2026-09-08
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Path traversal allowing remote tampering
Action: Patch
AI Analysis

Impact

This vulnerability is caused by an improper limitation of a pathname to a restricted directory, enabling path traversal attacks. An attacker who can influence the path used by Visual Studio Code may manipulate files outside the intended directory, allowing tampering with code or configuration files over the network. The weakness is identified as CWE-22.

Affected Systems

Microsoft Visual Studio Code is affected. No specific version ranges are provided in the CNA data, so all installations that have not applied the patch are considered vulnerable.

Risk and Exploitability

The CVSS score of 6.5 indicates a moderate severity vulnerability. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is remote, where an attacker can provide a specially crafted path that is processed by Visual Studio Code or its extensions. Successful exploitation would allow the attacker to tamper with files accessible to the application, potentially leading to code injection or privilege escalation if additional weaknesses exist.

Generated by OpenCVE AI on September 9, 2026 at 04:05 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Install the latest Visual Studio Code release that includes the path traversal fix.
  • Check the Microsoft Security Response Center for updates and apply them promptly.
  • Disable or limit any extensions or features that allow remote or external file access to reduce the potential attack surface.

Generated by OpenCVE AI on September 9, 2026 at 04:05 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 11 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:microsoft:visual_studio_code:*:*:*:*:*:-:*:*

Tue, 08 Sep 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 08 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Description Improper limitation of a pathname to a restricted directory ('path traversal') in Visual Studio Code allows an unauthorized attacker to perform tampering over a network.
Title Visual Studio Code Tampering Vulnerability
First Time appeared Microsoft
Microsoft visual Studio Code
Weaknesses CWE-22
CPEs cpe:2.3:a:microsoft:visual_studio_code:*:*:*:*:*:*:*:*
Vendors & Products Microsoft
Microsoft visual Studio Code
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N/E:U/RL:O/RC:C'}


Subscriptions

Microsoft Visual Studio Code
cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-09-25T21:33:52.248Z

Reserved: 2026-08-26T18:46:26.214Z

Link: CVE-2026-81377

cve-icon Vulnrichment

Updated: 2026-09-08T18:24:23.356Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-08T18:20:53.937

Modified: 2026-09-11T21:09:23.980

Link: CVE-2026-81377

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-10T05:45:06Z

Weaknesses
  • CWE-22

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')