Skip to content
MicrosoftGHSA-9mw4-h26x-gfxw

Workspace Trust Security Feature Bypass Vulnerability

HighCVE-2026-57101 · Published Jul 14, 2026

A security feature bypass vulnerability exists in VS Code 1.128.0 and earlier versions where, under certain conditions, specially crafted notebook content could bypass security restrictions in Restricted Mode. ### Patches The fix is available starting with **VS Code 1.128.1**. The fix mitigates this attack by improving how untrusted notebook content is handled. ### Workarounds Do not open notebooks from untrusted sources on versions of VS Code <=1.128.0. ### References * The patch for this can be found at https://github.com/microsoft/vscode/commit/bc2d56c6f8da22a4bd31f741fcb034208770f158 * An issue for this can be found at https://github.com/microsoft/vscode/issues/325839 * MSRC details for this can be found at https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-57101

GitHub advisory

Affected versions

PackageAffectedFixed in
vscode
Product
< 1.128.11.128.1
Details and references

More Microsoft advisories

All Microsoft
Advisory
Secret exfiltration vulnerability
HighJul 14
Remote Code Execution Vulnerability
HighJul 14
Microsoft .NET 8.0: unsafe deserialization
High7.8Jul 14
Microsoft .NET 8.0: code injection
High7.8Jul 14
Microsoft .NET 10.0: resource exhaustion
High7.5Jul 14
Microsoft .NET 10.0: spoofing
Medium6.5Jul 14

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.