
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-45496 is a path traversal vulnerability (CWE-22) in Microsoft Visual Studio Code that allows a local attacker to bypass a security feature by exploiting improper limitation of a pathname to a restricted directory. It affects all versions of Visual Studio Code from 1.0.0 up to (but not including) 1.128.1. The vulnerability was disclosed by Microsoft on July 14, 2026, as part of the July 2026 Patch Tuesday release, with NVD analysis completed on July 16, 2026. It carries a CVSS v3.1 base score of 5.5 (Medium) (Microsoft MSRC, Rapid7 Blog).
The root cause is CWE-22 (Improper Limitation of a Pathname to a Restricted Directory), where Visual Studio Code fails to adequately validate or sanitize file path inputs, allowing traversal sequences (e.g., ../) to escape a restricted directory boundary. Exploitation requires local access with low privileges and no user interaction (per NIST's CVSS assessment), though Microsoft's own CNA scoring indicates no privileges are required but user interaction is needed — reflecting some ambiguity in the attack preconditions. The attack vector is local, meaning the attacker must have access to the system running the vulnerable VS Code instance. No public proof-of-concept or technical write-up detailing the specific vulnerable code path has been identified at this time (Microsoft MSRC, Feedly).
Successful exploitation allows a low-privileged local attacker to read files outside of the intended restricted directory, resulting in a high confidentiality impact with no integrity or availability impact. The vulnerability is classified as a Security Feature Bypass, meaning it circumvents access controls designed to limit file system access within VS Code's sandboxed or restricted context. The scope is unchanged, limiting the impact to the local system and reducing the risk of direct lateral movement, though sensitive files read via path traversal (e.g., credentials, configuration files) could facilitate further attacks (Microsoft MSRC, Feedly).
Microsoft has released a patch in Visual Studio Code version 1.128.1, which resolves this vulnerability. Users should update VS Code to version 1.128.1 or later immediately via the built-in update mechanism (Help > Check for Updates) or by downloading the latest release from the official VS Code website. As a workaround, organizations should restrict local access to VS Code installations to trusted users only and apply the principle of least privilege on systems running VS Code. No configuration-only workaround has been published by Microsoft (Microsoft MSRC, Feedly).
The vulnerability was covered as part of broader July 2026 Patch Tuesday roundups by security vendors including Rapid7, Lansweeper, NSFOCUS, and Kaspersky, though it did not receive significant standalone attention given its medium severity and local-only attack vector. No notable independent researcher commentary or social media discussion specific to this CVE has been identified (Rapid7 Blog, Lansweeper Blog, NSFOCUS).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."