CVE-2026-81383
Analyzed Analyzed - Analysis Complete

Incorrectly Resolved Name Disclosure in Visual Studio Code

Vulnerability report for CVE-2026-81383, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-08

Last updated on: 2026-09-10

Assigner: Microsoft Corporation

Description

Use of incorrectly-resolved name or reference in Visual Studio Code allows an unauthorized attacker to disclose information over a network.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-08
Last Modified
2026-09-10
Generated
2026-09-29
AI Q&A
2026-09-10
EPSS Evaluated
2026-09-27
NVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
microsoft visual_studio_code to 1.136.2 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-706 The product uses a name or reference to access a resource, but the name/reference resolves to a resource that is outside of the intended control sphere.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability in Visual Studio Code involves an attacker exploiting incorrectly-resolved names or references to disclose sensitive information over a network. It requires user interaction and has a high impact on confidentiality.

Impact Analysis

An unauthorized attacker could access confidential data transmitted or stored in Visual Studio Code. The high confidentiality impact means sensitive information like credentials or personal data may be exposed.

Compliance Impact

This vulnerability could lead to unauthorized data disclosure, violating GDPR's data protection principles and HIPAA's confidentiality requirements. Organizations may face compliance penalties if exploited.

Mitigation Strategies

Update Visual Studio Code to the latest version to ensure the vulnerability is patched. Disable network access to Visual Studio Code if not required. Monitor network traffic for suspicious activity related to information disclosure.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-81383. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart