CVE-2026-41611
low
CVSS v3
3.3
CVSS v2
—
VIR risk
3.3
Description
Improper neutralization of script-related html tags in a web page (basic xss) in Visual Studio Code allows an unauthorized attacker to execute code locally.
Predictions
Exploit likelihood
34%
Patch ETA
—
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
Vendor advisory: secure@microsoft.com — https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-41611
Application impact
| Vendor | Product | Versions | Fixed |
|---|---|---|---|
| microsoft | visual_studio_code | {"endExcluding":"1.119.1"} | 1.119.1 |
References
CWEs
CWE-77 CWE-80 CWE-79
Verify integrity in audit chain (admin only). AS-IS.