Skip to content
MicrosoftGHSA-5vj9-2628-2rm4

Remote Code Execution Vulnerability in webviews

MediumCVE-2026-41611 · Published May 12, 2026

## VS Code - Remote Code Execution Vulnerability A remote code execution vulnerability exists in VS Code 1.119.0 and earlier versions with the internal protocol webviews use to load the VS Code controlled root webview content. This could result in untrusted scripts being run inside the webview ### Patches The fix is available starting with **VS Code 1.119.1**. The fix (https://github.com/microsoft/vscode/commit/1dbe28533fe4204dcd3c3e30a05e22c6ba307145) mitigates this attack by making sure the correctly sized buffer is passed to the webview protocol provider ### Workarounds Do not open webviews that can load untrusted content ### References * The patch for this can be found at https://github.com/microsoft/vscode/commit/1dbe28533fe4204dcd3c3e30a05e22c6ba307145 * MSRC details for this can be found at https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-41611

GitHub advisory

Affected versions

PackageAffectedFixed in
vscode
Product
< 1.119.11.119.1
Details and references

More Microsoft advisories

All Microsoft

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.