AUGUST 15, 2026
Live Feed
Back to database
Case File

CVE-2026-47285

MEDIUM · CVSS 6.5 EPSS 0.89%

Source: NVD + CISA KEV + EPSS · Published 2026-08-11 · Last synced 2026-08-15

CyberRota Analysis

AI-Generated

Visual Studio Code is vulnerable to command injection due to improper handling of special elements, which could allow an unauthorized attacker to disclose sensitive information over a network. Organizations using this software should prioritize addressing this vulnerability to mitigate potential data leaks and ensure the security of their development environments.

CVE
CVE-2026-47285
Severity
MEDIUM
CVSS
6.5
EPSS
0.89%

Original NVD Description

Improper neutralization of special elements used in a command ('command injection') in Visual Studio Code allows an unauthorized attacker to disclose information over a network.