
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-50520 is a command injection vulnerability in Microsoft Visual Studio Code that allows an unauthenticated local attacker to execute arbitrary code. It affects all versions of Visual Studio Code from 1.0.0 up to (but not including) 1.128.1. The vulnerability was disclosed and patched on July 14, 2026, as part of Microsoft's July 2026 Patch Tuesday release. It carries a CVSS v3.1 base score of 8.4 (High) (Microsoft MSRC).
The vulnerability is classified as CWE-77 (Improper Neutralization of Special Elements used in a Command — 'Command Injection'), meaning VS Code fails to properly sanitize special characters or metacharacters before passing user-influenced input to an underlying system command. An attacker with local access to the system can craft malicious input that is interpreted as part of a command, resulting in arbitrary code execution within the context of the VS Code process. No privileges are required and no user interaction is needed to trigger the flaw, making it exploitable by any local user or process on the affected system (Microsoft MSRC).
Successful exploitation grants an attacker the ability to execute arbitrary code with the privileges of the Visual Studio Code process, resulting in high confidentiality, integrity, and availability impact. An attacker could read sensitive files accessible to the VS Code process, modify system configuration, install malware, or use the compromised process as a pivot point for further lateral movement within the local environment. The technical impact is assessed as 'total' by CISA-ADP, indicating full compromise of the affected process's security context (Microsoft MSRC).
cmd.exe, powershell.exe, bash, sh, curl, wget) that are not typical for normal IDE operation.code.exe or code binary spawning shell commands).Microsoft has released a patch in Visual Studio Code version 1.128.1, which resolves this vulnerability. Users should update to version 1.128.1 or later immediately via the VS Code built-in update mechanism or by downloading the latest release from the official Microsoft website. As an interim measure, restrict local system access to only trusted users on machines running vulnerable VS Code versions, and monitor for suspicious command execution originating from VS Code processes (Microsoft MSRC).
Rapid7 covered this vulnerability as part of their July 2026 Patch Tuesday analysis (Rapid7 Blog). Kaspersky also catalogued the vulnerability in their threat intelligence database. Community coverage has been moderate, consistent with a local-only attack vector and no active exploitation observed at time of disclosure.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."