HIGH 7.4 NVD
CVE-2026-78461
Improper limitation of a pathname to a restricted directory ('path traversal') in Visual Studio Code allows an unauthorized attacker to bypass a security featur
Improper limitation of a pathname to a restricted directory ('path traversal') in Visual Studio Code allows an unauthorized attacker to bypass a security feature over a network.
Affected Products
- microsoft/visual_studio_code
References
This high severity vulnerability with a CVSS score of 7.4 was published on 2026-09-08 via NVD. Affected: microsoft/visual_studio_code.
vulnfeed aggregates 12842 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.