Description
Improper neutralization of input during web page generation ('cross-site scripting') in Visual Studio Code allows an unauthorized attacker to bypass a security feature locally.
Problem types
CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CWE-59: Improper Link Resolution Before File Access ('Link Following')
CWE-200: Exposure of Sensitive Information to an Unauthorized Actor
Product status
References
msrc.microsoft.com/update-guide/vulnerability/CVE-2026-41610 (Visual Studio Code Security Feature Bypass Vulnerability)