CVE-2025-55319: Microsoft Visual Studio Code
Critical severity, CVSS 9.8. EPSS: 0.9% chance of exploitation in the next 30 days.
Ai command injection in Agentic AI and Visual Studio Code allows an unauthorized attacker to execute code over a network.
Affected products
- Microsoft Visual Studio Code: before 1.104.0 (fixed in 1.104.0)
Published 2025-09-12. Last modified 2026-06-17.