CVE-2025-55319: Microsoft Visual Studio Code

Critical severity, CVSS 9.8. EPSS: 0.9% chance of exploitation in the next 30 days.

Ai command injection in Agentic AI and Visual Studio Code allows an unauthorized attacker to execute code over a network.

Affected products

  • Microsoft Visual Studio Code: before 1.104.0 (fixed in 1.104.0)

Published 2025-09-12. Last modified 2026-06-17.