
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-55319 is an AI command injection vulnerability in the Agentic AI component of Microsoft Visual Studio Code that allows an unauthorized attacker to execute arbitrary code over a network. The vulnerability affects Visual Studio Code versions prior to 1.104.0 and was publicly disclosed on September 11, 2025, with a patch released on September 9, 2025. It carries a CVSS v3.1 base score of 9.8 (Critical) per NVD, with no privileges required and no user interaction needed (Microsoft MSRC).
The vulnerability is classified as CWE-77 (Improper Neutralization of Special Elements used in a Command — 'Command Injection'), rooted in insufficient sanitization of user-controlled input passed to the Agentic AI component within VS Code. An attacker can inject malicious commands through the AI-assisted coding feature, which are then executed by the underlying system without proper validation. The attack vector is network-based, requires no authentication or privileges, and — per the NVD CVSS scoring — no user interaction, making it exploitable remotely with low complexity. A technical write-up by ZeroPath provides additional analysis of the injection mechanics (ZeroPath Blog, Microsoft MSRC).
Successful exploitation results in remote code execution (RCE) on the affected developer workstation, with high impact to confidentiality, integrity, and availability. Attackers could access sensitive source code repositories, credentials stored in the development environment, and use the compromised machine as a pivot point for lateral movement within corporate networks. Given VS Code's ubiquity in software development environments, the blast radius of exploitation could extend to CI/CD pipelines and internal infrastructure (Microsoft MSRC, ZeroPath Blog).
cmd.exe, powershell.exe, /bin/bash, curl, wget) with unusual arguments or parent-child relationships.Microsoft released a patch on September 9, 2025; users should update Visual Studio Code to version 1.104.0 or later immediately. No specific configuration-based workaround has been published, so upgrading is the primary remediation. Organizations should deploy automated update mechanisms for VS Code across all developer workstations and verify patch application using vulnerability scanners such as Nessus (Plugin 265431) or Qualys (QID 92309) (Microsoft MSRC, Tenable).
German technology outlet Heise reported on the vulnerability, describing it as a "malicious code loophole in Microsoft Agentic AI and Visual Studio Code" that has since been closed (Heise). Security researcher Rod Trent highlighted the issue in a newsletter-style security check-in, and it was discussed in the Action1 community's Patch Tuesday roundup for context on the September 2025 update cycle. Greenbone included CVE-2025-55319 in its September 2025 threat report covering critical CVEs (Greenbone). Overall community sentiment reflects concern given VS Code's widespread adoption in enterprise development environments.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."