CVE-2026-70336HighCVSS 8.8
Visual Studio Code Remote Code Execution Vulnerability
🔗 CVE IDs covered (1)
📋 Description
Improper control of generation of code ('code injection') in Visual Studio Code allows an unauthorized attacker to execute code over a network.
🎯 Affected products1
- Visual Studio Code
✅ Remediation
KBRelease Notes (Security Update) — fixed build 1.132.1