Skip to content
MicrosoftGHSA-h9j4-x76r-fvj4

TerminalInstance._createProcess - Workspace Trust bypass via terminal waitOnExit

High7.8CVE-2026-69278 · Published Aug 11, 2026

## VS Code - Terminal Workspace Trust Bypass Vulnerability A command execution vulnerability exists in VS Code 1.132.0 and earlier versions where terminal process creation can continue after workspace trust is denied or dismissed. Terminal process creation can also continue in an empty workspace after VS Code detects an unexpected working directory. An attacker could exploit these issues by convincing a user to open a malicious workspace in VS Code. ### Patches The fix will be available starting with **VS Code 1.132.1**. The fix (https://github.com/microsoft/vscode/commit/3154a68fc151bcafe371f89d197412645e6a7616) mitigates these issues by stopping terminal process creation immediately when either security check rejects the launch. ### Workarounds Do not open untrusted workspaces. If an untrusted workspace is already open, do not launch an integrated terminal. ### References * The patch for this can be found at https://github.com/microsoft/vscode/commit/3154a68fc151bcafe371f89d197412645e6a7616 * MSRC incident details can be found at https://portal.microsofticm.com/imp/v5/incidents/details/31000000607658/summary * MSRC details for these issues can be found at https://msrc.mic...

GitHub advisory

Affected versions

PackageAffectedFixed in
vscode
Product
< 1.132.11.132.1
Details and references

## VS Code - Terminal Workspace Trust Bypass Vulnerability A command execution vulnerability exists in VS Code 1.132.0 and earlier versions where terminal process creation can continue after workspace trust is denied or dismissed. Terminal process creation can also continue in an empty workspace after VS Code detects an unexpected working directory. An attacker could exploit these issues by convincing a user to open a malicious workspace in VS Code. ### Patches The fix will be available starting with **VS Code 1.132.1**. The fix (https://github.com/microsoft/vscode/commit/3154a68fc151bcafe371f89d197412645e6a7616) mitigates these issues by stopping terminal process creation immediately when either security check rejects the launch. ### Workarounds Do not open untrusted workspaces. If an untrusted workspace is already open, do not launch an integrated terminal. ### References * The patch for this can be found at https://github.com/microsoft/vscode/commit/3154a68fc151bcafe371f89d197412645e6a7616 * MSRC incident details can be found at https://portal.microsofticm.com/imp/v5/incidents/details/31000000607658/summary * MSRC details for these issues can be found at https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69278

CVSS 3.1
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Severity from
GitHub (reviewed advisory)

More Microsoft advisories

All Microsoft

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.