Skip to content
MicrosoftGHSA-6xq8-9qf3-p6qv

Workspace trust for MCP servers

LowCVE-2026-21518 · Published Feb 10, 2026

## VS Code - Remote Code Execution Vulnerability A remote code execution vulnerability exists in VS Code 1.109.0 and earlier versions where workspace trust was not always demanded to start MCP servers. ### Patches The fix is available starting with **VS Code 1.109.1**. The fix mitigates this attack by performing explicitly demanding trust before starting MCP servers. ### Workarounds Do not use interact with Copilot on untrusted workspaces in VS Code versions prior to 1.109.1. ### References * The patch for this can be found at TODO * An issue for this can be found at [TODO](https://github.com/microsoft/vscode/issues/294184) * MSRC details for this can be found at https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-21518

GitHub advisory

Affected versions

PackageAffectedFixed in
vscode
Product
< 1.109.11.109.1
Details and references

More Microsoft advisories

All Microsoft

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.