Skip to content
MicrosoftGHSA-r2gr-w3c8-wvqv

Visual Studio Code Workspace Trust bypass through attacker-controlled services

Critical9.6CVE-2026-81376 · Published Sep 8, 2026

## Impact A security feature bypass vulnerability exists in Visual Studio Code 1.136.1 and earlier versions. An attacker could convince a user to open a specially crafted Visual Studio Code workspace that causes Visual Studio Code to connect to an attacker-controlled service while the workspace is open in Restricted Mode. Due to incomplete enforcement of Workspace Trust restrictions, the crafted workspace could bypass protections intended to prevent content in untrusted workspaces from running commands or code. Successful exploitation could allow an attacker to access local data or execute code in the context of the user. User interaction is required because the user must open the crafted workspace. However, the user does not need to grant trust to the workspace for exploitation to occur. ## Patches The fix is available starting with **Visual Studio Code 1.136.2**. The fix ([0684cb5](https://github.com/microsoft/vscode/commit/0684cb5905a3f23156f45a28135326e09310ff4d)) ensures that restricted workspace settings are correctly identified and filtered when processing nested configuration objects. Users should update to Visual Studio Code 1.136.2 or later. ## Workarounds Do not...

GitHub advisory

Affected versions

PackageAffectedFixed in
Visual Studio Code
Product
< 1.136.21.136.2
Details and references

## Impact A security feature bypass vulnerability exists in Visual Studio Code 1.136.1 and earlier versions. An attacker could convince a user to open a specially crafted Visual Studio Code workspace that causes Visual Studio Code to connect to an attacker-controlled service while the workspace is open in Restricted Mode. Due to incomplete enforcement of Workspace Trust restrictions, the crafted workspace could bypass protections intended to prevent content in untrusted workspaces from running commands or code. Successful exploitation could allow an attacker to access local data or execute code in the context of the user. User interaction is required because the user must open the crafted workspace. However, the user does not need to grant trust to the workspace for exploitation to occur. ## Patches The fix is available starting with **Visual Studio Code 1.136.2**. The fix ([0684cb5](https://github.com/microsoft/vscode/commit/0684cb5905a3f23156f45a28135326e09310ff4d)) ensures that restricted workspace settings are correctly identified and filtered when processing nested configuration objects. Users should update to Visual Studio Code 1.136.2 or later. ## Workarounds Do not open Visual Studio Code workspaces from untrusted sources. Keep Workspace Trust enabled and do not grant trust to unfamiliar workspaces. These precautions reduce exposure but are not a substitute for updating Visual Studio Code. ## References - [Visual Studio Code issue #335112](https://github.com/microsoft/vscode/issues/335112) - [Fix commit 0684cb5](https://github.com/microsoft/vscode/commit/0684cb5905a3f23156f45a28135326e09310ff4d) - [MSRC entry for CVE-2026-81376](https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-81376) - [Visual Studio Code Workspace Trust documentation](https://code.visualstudio.com/docs/editor/workspace-trust)

CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
Severity from
GitHub (reviewed advisory)
Weakness
CWE-693, CWE-1023

More Microsoft advisories

All Microsoft
Advisory
Microsoft Skype for Business: spoofing
High8.3Sep 8
Microsoft Skype for Business: cross-site scripting
Medium6.5Sep 8
Microsoft Skype for Business: spoofing
High7.1Sep 8
Microsoft Skype for Business: information disclosure
Medium6.5Sep 8
Microsoft Skype for Business: integer overflow
High7.5Sep 8
Microsoft Skype for Business: out-of-bounds read
Medium6.5Sep 8

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.