Description
Use of incorrectly-resolved name or reference in Visual Studio Code allows an unauthorized attacker to disclose information over a network.
Published: 2026-09-08
Score: 7.4 High
EPSS: < 1% Very Low
KEV: No
Impact: Information Disclosure
Action: Patch
AI Analysis

Impact

In Visual Studio Code, an incorrectly resolved name or reference can be exploited by an unauthorized attacker to disclose information across a network. The flaw allows remote access to data that the attacker should not see, potentially exposing configuration details, credentials, or other sensitive content. The weakness is classified as CWE-706, reflecting misuse of authority or privileges.

Affected Systems

The affected product is Microsoft Visual Studio Code. No specific version information is defined in the vulnerability data, so any installation of Visual Studio Code that has not applied Microsoft’s latest security update is potentially at risk.

Risk and Exploitability

With a CVSS score of 7.4 the vulnerability represents a high risk to confidentiality. The EPSS score is not available, and the vulnerability is not listed in CISA’s KEV catalog. Likely exploitation requires network connectivity to the instance running VS Code, such as through remote debugging or extension management features, and the attacker must be able to send malformed requests that trigger the name resolution error.

Generated by OpenCVE AI on September 9, 2026 at 02:46 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update Visual Studio Code to the latest version that contains the vendor patch addressing the information disclosure.
  • Disable or restrict network features that expose VS Code to untrusted connections, such as disabling remote debugging or limiting extension installation to trusted sources.
  • Enable and enforce application-layer access controls; regularly review firewall and network exposure of development workstations.

Generated by OpenCVE AI on September 9, 2026 at 02:46 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 10 Sep 2026 15:00:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:microsoft:visual_studio_code:*:*:*:*:*:-:*:*

Tue, 08 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 08 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Description Use of incorrectly-resolved name or reference in Visual Studio Code allows an unauthorized attacker to disclose information over a network.
Title Visual Studio Code Information Disclosure Vulnerability
First Time appeared Microsoft
Microsoft visual Studio Code
Weaknesses CWE-706
CPEs cpe:2.3:a:microsoft:visual_studio_code:*:*:*:*:*:*:*:*
Vendors & Products Microsoft
Microsoft visual Studio Code
References
Metrics cvssV3_1

{'score': 7.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:N/A:N/E:U/RL:O/RC:C'}


Subscriptions

Microsoft Visual Studio Code
cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-09-25T21:38:37.334Z

Reserved: 2026-08-26T18:46:26.214Z

Link: CVE-2026-81383

cve-icon Vulnrichment

Updated: 2026-09-08T19:59:16.572Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-08T18:20:54.593

Modified: 2026-09-10T14:48:34.500

Link: CVE-2026-81383

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-10T03:00:08Z

Weaknesses
  • CWE-706

    Use of Incorrectly-Resolved Name or Reference