SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-70334

HIGH · CVSS 7.8 EPSS 0.43%

Source: NVD + CISA KEV + EPSS · Published 2026-09-08 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

An incomplete list of disallowed inputs in Visual Studio Code enables unauthorized local attackers to bypass security features, potentially leading to unauthorized access or manipulation of the development environment. Organizations using Visual Studio Code should prioritize addressing this vulnerability to mitigate risks associated with local exploitation. Users and developers relying on this IDE for sensitive projects are particularly at risk and should implement any available patches or mitigations promptly.

CVE
CVE-2026-70334
Severity
HIGH
CVSS
7.8
EPSS
0.43%

Original NVD Description

Incomplete list of disallowed inputs in Visual Studio Code allows an unauthorized attacker to bypass a security feature locally.

Related CVEs

Other vulnerabilities affecting the same vendor(s)