CVE-2025-26631: Microsoft Visual Studio Code

High severity, CVSS 7.3. EPSS: 0.6% chance of exploitation in the next 30 days.

Uncontrolled search path element in Visual Studio Code allows an authorized attacker to elevate privileges locally.

Affected products

  • Microsoft Visual Studio Code: before 1.98.0 (fixed in 1.98.0)

Published 2025-03-11. Last modified 2026-06-17.