CyberRota Analysis
AI-GeneratedVisual Studio Code is vulnerable to command injection due to improper handling of special elements, which could allow an unauthorized attacker to disclose sensitive information over a network. Organizations using this software should prioritize addressing this vulnerability to mitigate potential data leaks and ensure the security of their development environments.
CVE
CVE-2026-47285
Severity
MEDIUM
CVSS
6.5
EPSS
0.89%
Original NVD Description
Improper neutralization of special elements used in a command ('command injection') in Visual Studio Code allows an unauthorized attacker to disclose information over a network.