CVE-2025-26631: Microsoft Visual Studio Code
High severity, CVSS 7.3. EPSS: 0.6% chance of exploitation in the next 30 days.
Uncontrolled search path element in Visual Studio Code allows an authorized attacker to elevate privileges locally.
Affected products
- Microsoft Visual Studio Code: before 1.98.0 (fixed in 1.98.0)
Published 2025-03-11. Last modified 2026-06-17.