Workspace trust for MCP servers
LowCVE-2026-21518 · Published Feb 10, 2026
## VS Code - Remote Code Execution Vulnerability A remote code execution vulnerability exists in VS Code 1.109.0 and earlier versions where workspace trust was not always demanded to start MCP servers. ### Patches The fix is available starting with **VS Code 1.109.1**. The fix mitigates this attack by performing explicitly demanding trust before starting MCP servers. ### Workarounds Do not use interact with Copilot on untrusted workspaces in VS Code versions prior to 1.109.1. ### References * The patch for this can be found at TODO * An issue for this can be found at [TODO](https://github.com/microsoft/vscode/issues/294184) * MSRC details for this can be found at https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-21518
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| vscode Product | < 1.109.1 | 1.109.1 |
Details and references
- Severity from
- GitHub (reviewed advisory)
More Microsoft advisories
All Microsoft| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| May 12 | MCP Deeplink Install Lacked Essential Information | High8.8 | No fix yet |
| May 12 | Apply patch sensitive file workaround | High8.8 | No fix yet |
| May 12 | Remote Code Execution Vulnerability in webviews | Medium | 1.119.1 |
| May 12 | Remote Code Execution Vulnerability with Jupyter notebook markdown rendering in untrusted workspaces | Medium | 1.119.1 |
| Mar 25 | openssl on Windows built with openssldir set from the build machine (Uncontrolled Search Path Element) | High7.8 | 3.6.1#3 |
| Feb 10 | Terminal auto replies restriction | High8.0 | 1.109.1 |