Skip to content
MicrosoftGHSA-vww8-mqc2-4x8v

Information Disclosure through Automatic Remote Image Fetch in Chat

Medium5.3CVE-2026-81380 · Published Sep 8, 2026

### Impact An information disclosure vulnerability existed in VS Code builds up to and including version 1.136.1 when agent-provided Markdown contained an image or other media element with a remote source. Chat's remote-image policy replaced the element with plaintext, but the policy ran only after sanitized content had been materialized as DOM. The browser could therefore issue the request before the element was replaced. An attacker able to place indirect prompt-injection instructions in external content could cause an agent to encode workspace data in a generated media URL. Rendering the response could send that URL to an attacker-controlled server without a link click or a separate network-tool confirmation. Rendering restored chat history could repeat the request. ### Patches The fix (https://github.com/microsoft/vscode/commit/88e44fa0e00b08f7758b4f6d05632e4fd5e4df6f) is is available in VS Code builds starting with **1.136.2**. Additional media-source validation now runs during DOM sanitization, before sanitized content is attached to the rendered document. Source, poster, and non-anchor resource references are validated; network-backed file resources and raw stylesheet el...

GitHub advisory

Affected versions

PackageAffectedFixed in
vscode
Product
< 1.136.21.136.2
Details and references

### Impact An information disclosure vulnerability existed in VS Code builds up to and including version 1.136.1 when agent-provided Markdown contained an image or other media element with a remote source. Chat's remote-image policy replaced the element with plaintext, but the policy ran only after sanitized content had been materialized as DOM. The browser could therefore issue the request before the element was replaced. An attacker able to place indirect prompt-injection instructions in external content could cause an agent to encode workspace data in a generated media URL. Rendering the response could send that URL to an attacker-controlled server without a link click or a separate network-tool confirmation. Rendering restored chat history could repeat the request. ### Patches The fix (https://github.com/microsoft/vscode/commit/88e44fa0e00b08f7758b4f6d05632e4fd5e4df6f) is is available in VS Code builds starting with **1.136.2**. Additional media-source validation now runs during DOM sanitization, before sanitized content is attached to the rendered document. Source, poster, and non-anchor resource references are validated; network-backed file resources and raw stylesheet elements are rejected. Disallowed media elements are converted to plaintext without activating their source. Genuinely local file and data images and KaTeX rendering remain supported. ## Workarounds Until a build containing the fix is installed, do not use Agent mode with untrusted external content in a workspace containing sensitive data. Avoid opening or reopening conversations that contain agent-generated remote images. Organizations can also disable AI features with the `chat.disableAIFeatures` policy. ### References * The patch for this can be found at https://github.com/microsoft/vscode/commit/88e44fa0e00b08f7758b4f6d05632e4fd5e4df6f * An issue for this can be found at https://github.com/microsoft/vscode/issues/335125 * MSRC details for CVE-2026-81380 can be found at https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-81380

CVSS 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N
Severity from
GitHub (reviewed advisory)

More Microsoft advisories

All Microsoft
Advisory
Microsoft Skype for Business: spoofing
High8.3Sep 8
Microsoft Skype for Business: cross-site scripting
Medium6.5Sep 8
Microsoft Skype for Business: spoofing
High7.1Sep 8
Microsoft Skype for Business: information disclosure
Medium6.5Sep 8
Microsoft Skype for Business: integer overflow
High7.5Sep 8
Microsoft Skype for Business: out-of-bounds read
Medium6.5Sep 8

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.