Improper neutralization of script-related html tags in a web page (basic xss) in Visual Studio Code allows an unauthorized attacker to execute code locally.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Tue, 12 May 2026 17:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Improper neutralization of script-related html tags in a web page (basic xss) in Visual Studio Code allows an unauthorized attacker to execute code locally. | |
| Title | Visual Studio Code Remote Code Execution Vulnerability | |
| First Time appeared |
Microsoft
Microsoft visual Studio Code |
|
| Weaknesses | CWE-77 CWE-80 |
|
| CPEs | cpe:2.3:a:microsoft:visual_studio_code:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Microsoft
Microsoft visual Studio Code |
|
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: microsoft
Published:
Updated: 2026-05-12T17:53:55.133Z
Reserved: 2026-04-21T22:14:12.923Z
Link: CVE-2026-41611
No data.
Status : Received
Published: 2026-05-12T18:17:22.980
Modified: 2026-05-12T18:17:22.980
Link: CVE-2026-41611
No data.
OpenCVE Enrichment
Updated: 2026-05-12T21:30:24Z