Skip to content
MicrosoftGHSA-vcpf-2mpp-vx3v

Information disclosure vulnerability

MediumCVE-2026-47285 · Published Aug 11, 2026

An information disclosure vulnerability exists in VS Code 1.132.0 and earlier versions where malicious extension and webview contents could read sensitive data from reused internal buffers. ### Patches The fix is available starting with **VS Code 1.132.1**. The fix (https://github.com/microsoft/vscode/commit/ae7a28076f3076a10bd07b49cf7ff730c1773e61) mitigates this attack by copying the intended range of the internal buffer contents before sending to extensions. ### References * The patch for this can be found at https://github.com/microsoft/vscode/commit/ae7a28076f3076a10bd07b49cf7ff730c1773e61 * An issue for this can be found at https://github.com/microsoft/vscode/issues/330306 * MSRC details for this can be found at https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-47285

GitHub advisory

Affected versions

PackageAffectedFixed in
vscode
Product
< 1.132.11.132.1
Details and references

More Microsoft advisories

All Microsoft

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.