Workspace Trust Security Feature Bypass Vulnerability
HighCVE-2026-57101 · Published Jul 14, 2026
A security feature bypass vulnerability exists in VS Code 1.128.0 and earlier versions where, under certain conditions, specially crafted notebook content could bypass security restrictions in Restricted Mode. ### Patches The fix is available starting with **VS Code 1.128.1**. The fix mitigates this attack by improving how untrusted notebook content is handled. ### Workarounds Do not open notebooks from untrusted sources on versions of VS Code <=1.128.0. ### References * The patch for this can be found at https://github.com/microsoft/vscode/commit/bc2d56c6f8da22a4bd31f741fcb034208770f158 * An issue for this can be found at https://github.com/microsoft/vscode/issues/325839 * MSRC details for this can be found at https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-57101
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| vscode Product | < 1.128.1 | 1.128.1 |
Details and references
- Severity from
- GitHub (reviewed advisory)
More Microsoft advisories
All Microsoft| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Jul 14 | Secret exfiltration vulnerability | High | 1.128.1 |
| Jul 14 | Remote Code Execution Vulnerability | High | 1.128.1 |
| Jul 14 | Microsoft .NET 8.0: unsafe deserialization | High7.8 | 8.0.29+9 more |
| Jul 14 | Microsoft .NET 8.0: code injection | High7.8 | 8.0.29+10 more |
| Jul 14 | Microsoft .NET 10.0: resource exhaustion | High7.5 | 10.0.10+5 more |
| Jul 14 | Microsoft .NET 10.0: spoofing | Medium6.5 | 10.0.10+11 more |