Skip to content
MicrosoftGHSA-hwrx-jgf2-74hw

Remote Code Execution Vulnerability

HighCVE-2025-20570 · Published Apr 8, 2025

### Description A remote code execution vulnerability exists in VS Code 1.99.0 and earlier versions where another user within the same group could edit the $ZDOTDIR and have extra code executed in the integrated zshell. ### Patches The fix is available starting with **VS Code 1.99.1**. The fix (https://github.com/microsoft/vscode/commit/2f2e2c47d406976b6976ec6114eab8ac44d63513) mitigates this attack by setting the sticky bit and remove group and other permissions to restrict the folder to the user that created it. ### Workarounds Disable shell integration in VS Code by setting `"terminal.integrated.shellIntegration.enabled": false` or do not open a zshell within VS Code. ### References * The patch for this can be found at https://github.com/microsoft/vscode/commit/2f2e2c47d406976b6976ec6114eab8ac44d63513 * A github issue for this can be found at https://github.com/microsoft/vscode/issues/246012 * MSRC details for this can be found at https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-20570

GitHub advisory

Affected versions

PackageAffectedFixed in
vscode
Product
< 1.99.11.99.1
Details and references

More Microsoft advisories

All Microsoft
Advisory
Terminal auto replies restriction
High8.0Feb 10
Workspace trust for MCP servers
LowFeb 10
Security Feature Bypass Vulnerability
HighMay 13, 2025
Elevation of Privilege Vulnerability
HighFeb 11, 2025
Elevation of Privilege Vulnerability
MediumFeb 11, 2025
Visual Studio Code for Linux Remote Code Execution Vulnerability
HighOct 8, 2024

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.