CVE-2025-55319
Visual Studio Code vulnerability analysis and mitigation

Overview

CVE-2025-55319 is an AI command injection vulnerability in the Agentic AI component of Microsoft Visual Studio Code that allows an unauthorized attacker to execute arbitrary code over a network. The vulnerability affects Visual Studio Code versions prior to 1.104.0 and was publicly disclosed on September 11, 2025, with a patch released on September 9, 2025. It carries a CVSS v3.1 base score of 9.8 (Critical) per NVD, with no privileges required and no user interaction needed (Microsoft MSRC).

Technical details

The vulnerability is classified as CWE-77 (Improper Neutralization of Special Elements used in a Command — 'Command Injection'), rooted in insufficient sanitization of user-controlled input passed to the Agentic AI component within VS Code. An attacker can inject malicious commands through the AI-assisted coding feature, which are then executed by the underlying system without proper validation. The attack vector is network-based, requires no authentication or privileges, and — per the NVD CVSS scoring — no user interaction, making it exploitable remotely with low complexity. A technical write-up by ZeroPath provides additional analysis of the injection mechanics (ZeroPath Blog, Microsoft MSRC).

Impact

Successful exploitation results in remote code execution (RCE) on the affected developer workstation, with high impact to confidentiality, integrity, and availability. Attackers could access sensitive source code repositories, credentials stored in the development environment, and use the compromised machine as a pivot point for lateral movement within corporate networks. Given VS Code's ubiquity in software development environments, the blast radius of exploitation could extend to CI/CD pipelines and internal infrastructure (Microsoft MSRC, ZeroPath Blog).

Exploitation steps

  1. Reconnaissance: Identify targets running Visual Studio Code versions prior to 1.104.0 with the Agentic AI feature enabled, using asset inventory tools or network scanning.
  2. Craft malicious input: Prepare a payload containing command injection sequences (e.g., shell metacharacters or command delimiters) designed to be interpreted by the Agentic AI component.
  3. Deliver payload over network: Submit the crafted input to the vulnerable Agentic AI endpoint or feature within VS Code, exploiting the lack of input sanitization (CWE-77).
  4. Achieve code execution: The injected commands are executed by the underlying operating system in the context of the VS Code process, granting the attacker arbitrary code execution on the developer's workstation.
  5. Post-exploitation: Use the foothold to exfiltrate source code, harvest credentials, establish persistence, or pivot laterally within the network (ZeroPath Blog, Microsoft MSRC).

Indicators of compromise

  • Process: Unexpected child processes spawned by the VS Code process (e.g., cmd.exe, powershell.exe, /bin/bash, curl, wget) with unusual arguments or parent-child relationships.
  • Network: Outbound connections from the VS Code process or its children to unknown external IP addresses or domains, particularly on non-standard ports.
  • File System: New or modified files in the VS Code extension directories, user profile directories, or temp folders created by the VS Code process; unexpected scripts or executables dropped on disk.
  • Logs: OS-level audit logs (e.g., Windows Event ID 4688 or Linux auditd) showing process creation events with VS Code as the parent and shell interpreters as children; unusual command-line arguments referencing network resources.

Mitigation and workarounds

Microsoft released a patch on September 9, 2025; users should update Visual Studio Code to version 1.104.0 or later immediately. No specific configuration-based workaround has been published, so upgrading is the primary remediation. Organizations should deploy automated update mechanisms for VS Code across all developer workstations and verify patch application using vulnerability scanners such as Nessus (Plugin 265431) or Qualys (QID 92309) (Microsoft MSRC, Tenable).

Community reactions

German technology outlet Heise reported on the vulnerability, describing it as a "malicious code loophole in Microsoft Agentic AI and Visual Studio Code" that has since been closed (Heise). Security researcher Rod Trent highlighted the issue in a newsletter-style security check-in, and it was discussed in the Action1 community's Patch Tuesday roundup for context on the September 2025 update cycle. Greenbone included CVE-2025-55319 in its September 2025 threat report covering critical CVEs (Greenbone). Overall community sentiment reflects concern given VS Code's widespread adoption in enterprise development environments.

Additional resources


SourceThis report was generated using AI

Related Visual Studio Code vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-57102HIGH8.8
  • Visual Studio Code logoVisual Studio Code
  • cpe:2.3:a:microsoft:visual_studio_code
NoYesJul 14, 2026
CVE-2026-50520HIGH8.4
  • Visual Studio Code logoVisual Studio Code
  • cpe:2.3:a:microsoft:visual_studio_code
NoYesJul 14, 2026
CVE-2026-47282MEDIUM6.5
  • Visual Studio Code logoVisual Studio Code
  • cpe:2.3:a:microsoft:visual_studio_code
NoYesJul 14, 2026
CVE-2026-57101MEDIUM6.1
  • Visual Studio Code logoVisual Studio Code
  • cpe:2.3:a:microsoft:visual_studio_code
NoYesJul 14, 2026
CVE-2026-45496MEDIUM5.5
  • Visual Studio Code logoVisual Studio Code
  • cpe:2.3:a:microsoft:visual_studio_code
NoYesJul 14, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management