SEPTEMBER 13, 2026
Live Feed
Back to database
Case File

CVE-2026-50520

HIGH · CVSS 8.4 EPSS 0.25%

Source: NVD + CISA KEV + EPSS · Published 2026-07-14 · Last synced 2026-08-13

CyberRota Analysis

AI-Generated

Visual Studio Code is vulnerable to command injection due to improper handling of special elements, enabling unauthorized attackers to execute arbitrary code on affected systems. This high-severity flaw poses significant risks to users who utilize this development environment, particularly in scenarios where untrusted code is processed. Organizations and developers using Visual Studio Code should prioritize patching to mitigate potential exploitation.

CVE
CVE-2026-50520
Severity
HIGH
CVSS
8.4
EPSS
0.25%

Original NVD Description

Improper neutralization of special elements used in a command ('command injection') in Visual Studio Code allows an unauthorized attacker to execute code locally.

Related CVEs

Other vulnerabilities affecting the same vendor(s)