SEPTEMBER 12, 2026
Live Feed
Back to database
Case File

CVE-2026-57101

HIGH · CVSS 7.1 EPSS 0.44%

Source: NVD + CISA KEV + EPSS · Published 2026-07-14 · Last synced 2026-08-13

CyberRota Analysis

AI-Generated

Visual Studio Code is vulnerable to a cross-site scripting (XSS) flaw due to improper input neutralization during web page generation, enabling unauthorized attackers to bypass local security features. This vulnerability poses a high risk, particularly for developers and organizations using Visual Studio Code for application development, as it could lead to unauthorized access or manipulation of sensitive data. Users should prioritize applying patches or mitigations to safeguard their environments against potential exploitation.

CVE
CVE-2026-57101
Severity
HIGH
CVSS
7.1
EPSS
0.44%

Original NVD Description

Improper neutralization of input during web page generation ('cross-site scripting') in Visual Studio Code allows an unauthorized attacker to bypass a security feature locally.

Related CVEs

Other vulnerabilities affecting the same vendor(s)