AI for Security Summit: Join Figma, Perplexity & Wiz. [Register]

CVE-2026-81383
Visual Studio Code vulnerability analysis and mitigation

Overview

CVE-2026-81383 is an information disclosure vulnerability in Microsoft Visual Studio Code caused by use of an incorrectly-resolved name or reference (CWE-706). It allows an unauthenticated network attacker to disclose sensitive information when a user interacts with malicious content. Affected versions span from 1.0.0 up to (but not including) 1.136.2. The vulnerability was publicly disclosed on September 8, 2026, with patches released the same day as part of Microsoft's September 2026 Patch Tuesday. It carries a CVSS v3.1 base score of 7.4 (High) (Microsoft MSRC, GitHub Advisory).

Technical details

The root cause is classified as CWE-706 (Use of Incorrectly-Resolved Name or Reference), where Visual Studio Code resolves a name or reference to a resource outside its intended control sphere. The attack vector is network-based with low complexity, requiring no privileges but necessitating user interaction (e.g., opening a malicious file or clicking a crafted link within the editor). The changed scope indicates that the impact extends beyond the vulnerable component itself, potentially exposing resources in adjacent security contexts. No public proof-of-concept or detailed technical write-up has been published as of the disclosure date (Microsoft MSRC, GitHub Advisory).

Impact

Successful exploitation results in high confidentiality impact — an unauthorized attacker can disclose sensitive information accessible to the Visual Studio Code application, such as local files, tokens, or environment data. There is no integrity or availability impact. The changed scope suggests information from components beyond VS Code's immediate security boundary may be exposed, potentially including workspace secrets, credentials stored in configuration files, or data from connected remote environments (Microsoft MSRC, GitHub Advisory).

Exploitability

As of the disclosure date (September 8, 2026), there is no evidence of active in-the-wild exploitation and no public proof-of-concept has been published. The EPSS score is 0.0, reflecting a very low probability of near-term exploitation. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires user interaction, reducing the likelihood of automated or mass exploitation (Microsoft MSRC, GitHub Advisory).

Mitigation and workarounds

Microsoft released a patch on September 8, 2026 as part of Patch Tuesday; users should update Visual Studio Code to version 1.136.2 or later. As interim measures, users should avoid opening untrusted files or workspaces in VS Code and refrain from clicking links from unknown sources within the editor. Limiting network exposure of VS Code instances and auditing extensions for suspicious behavior are also recommended precautions (Microsoft MSRC, GitHub Advisory).

Community reactions

The vulnerability was covered as part of broader September 2026 Patch Tuesday roundups by security outlets including Rapid7 and GBHackers, which noted it among the 97+ vulnerabilities addressed that month. No notable individual researcher commentary or significant social media discussion specific to this CVE has been identified beyond standard patch advisory coverage (Rapid7 Blog, GBHackers).

Additional resources


SourceThis report was generated using AI

Related Visual Studio Code vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-81379HIGH8.2
  • Visual Studio Code logoVisual Studio Code
  • cpe:2.3:a:microsoft:visual_studio_code
NoYesSep 08, 2026
CVE-2026-81378HIGH8.2
  • Visual Studio Code logoVisual Studio Code
  • cpe:2.3:a:microsoft:visual_studio_code
NoYesSep 08, 2026
CVE-2026-81381HIGH7.5
  • Visual Studio Code logoVisual Studio Code
  • cpe:2.3:a:microsoft:visual_studio_code
NoYesSep 08, 2026
CVE-2026-81383HIGH7.4
  • Visual Studio Code logoVisual Studio Code
  • cpe:2.3:a:microsoft:visual_studio_code
NoYesSep 08, 2026
CVE-2026-81380MEDIUM5.3
  • Visual Studio Code logoVisual Studio Code
  • cpe:2.3:a:microsoft:visual_studio_code
NoYesSep 08, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management