Close Menu
    Facebook X (Twitter) Instagram
    Wifi PortalWifi Portal
    • Blogging
    • SEO & Digital Marketing
    • WiFi / Internet & Networking
    • Cybersecurity
    • Tech Tools & Mobile / Apps
    • Privacy & Online Earning
    Facebook X (Twitter) Instagram
    Wifi PortalWifi Portal
    Home»Cybersecurity»Flaws in popular VSCode extensions expose developers to attacks
    Cybersecurity

    Flaws in popular VSCode extensions expose developers to attacks

    adminBy adminFebruary 18, 2026No Comments3 Mins Read
    Facebook Twitter LinkedIn Telegram Pinterest Tumblr Reddit WhatsApp Email
    Flaws in popular VSCode extensions expose developers to attacks
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Flaws in popular VSCode extensions expose developers to attacks

    Vulnerabilities with high to critical severity ratings affecting popular Visual Studio Code (VSCode) extensions collectively downloaded more than 128 million times could be exploited to steal local files and execute code remotely.

    The security issues impact Live Server (CVE-2025-65715), Code Runner (CVE-2025-65716), Markdown Preview Enhanced (CVE-2025-65717), and Microsoft Live Preview (no identifier assigned).

    Researchers at application security company Ox Security discovered the flaws and tried to disclose them since June 2025. However, the researchers say that no maintainer responded.

    Wiz

    Remote code execution in IDE

    VSCode extensions are add-ons that expand the functionality of Microsoft’s integrated development environment (IDE). They can add language support, debugging tools, themes, and other functionality or customization options.

    They run with significant access to the local development environment, including files, terminals, and network resources.

    Ox Security published reports for each of the discovered flaws and warned that keeping the vulnerable extensions could expose the corporate environment to lateral movement, data exfiltration, and system takeover.

    An attacker exploiting the CVE-2025-65717 critical vulnerability in the Live Server extension (over 72 million downloads on VSCode) can steal local files by directing the target to a malicious webpage.

    The CVE-2025-65715 vulnerability in the Code Runner VSCode extension, with 37 million downloads, allows remote code execution by changing the extension’s configuration file. This could be achieved through tricking the target into pasting or applying a maliciously configuration snippet in the global settings.json file.

    Rated with a high-severity score of 8.8, CVE-2025-65716 affects the Markdown Preview Enhanced (8.5 million downloads) and can be leveraged to execute JavaScript via maliciously crafted Markdown file.

    Ox Security researchers discovered a one-click XSS vulnerability in versions of Microsoft Live Preview before 0.4.16. It can be exploited to access sensitive files on a developer’s machine. The extension has more than 11 million downloads on VSCode.

    The flaws in the extensions also apply to Cursor and Windsurf, which are AI-powered VSCode-compatible alternative IDEs.

    Ox Security’s report highlights that the risks associated with a threat actor leveraging the issues include pivoting on the network and stealing sensitive details like API keys and configuration files.

    Developers are advised to avoid running localhost servers unless necessary, opening untrusted HTML while they’re running, and applying untrusted configurations or pasting snippets into settings.json.

    Also, it is advisable to remove unnecessary extensions and only install those from reputable publishers, while monitoring for unexpected setting changes.


    tines

    Modern IT infrastructure moves faster than manual workflows can handle.

    In this new Tines guide, learn how your team can reduce hidden manual delays, improve reliability through automated response, and build and scale intelligent workflows on top of tools you already use.

    attacks Developers Expose Extensions Flaws popular VSCode
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Telegram Email
    Previous ArticleNew Report Helps Journalists Dig Deeper Into Police Surveillance Technology
    Next Article NotebookLM Slide Decks just got way more flexible
    admin
    • Website

    Related Posts

    California’s AB 412 Still Demands Developers Do The Impossible

    June 5, 2026

    Microsoft makes Linux developers feel more at home in Windows with Coreutils release

    June 5, 2026

    Encryption Consulting launches CertSecure Manager v3.3 with zero-touch certificate renewals

    May 20, 2026
    Add A Comment
    Leave A Reply Cancel Reply

    Search Blog
    About
    About

    At WifiPortal.tech, we share simple, easy-to-follow guides on cybersecurity, online privacy, and digital opportunities. Our goal is to help everyday users browse safely, protect personal data, and explore smart ways to earn online. Whether you’re new to the digital world or looking to strengthen your online knowledge, our content is here to keep you informed and secure.

    Trending Blogs

    The Integrated Search Brief That Aligns SEO, PPC & Content In The AI Search Era

    June 17, 2026

    Microsoft Ads expands LinkedIn targeting with job seniority filters

    June 17, 2026

    HPE Discover: Neri outlines an AI architecture built for agents

    June 17, 2026

    Schema, LLMs & The Low Bar For ‘Evidence’ In GEO

    June 17, 2026
    Categories
    • Blogging (96)
    • Cybersecurity (1,955)
    • Privacy & Online Earning (264)
    • SEO & Digital Marketing (1,512)
    • Tech Tools & Mobile / Apps (1,796)
    • WiFi / Internet & Networking (358)

    Subscribe to Updates

    Stay updated with the latest tips on cybersecurity, online privacy, and digital opportunities straight to your inbox.

    WifiPortal.tech is a blogging platform focused on cybersecurity, online privacy, and digital opportunities. We share easy-to-follow guides, tips, and resources to help you stay safe online and explore new ways of working in the digital world.

    Our Picks

    The Integrated Search Brief That Aligns SEO, PPC & Content In The AI Search Era

    June 17, 2026

    Microsoft Ads expands LinkedIn targeting with job seniority filters

    June 17, 2026

    HPE Discover: Neri outlines an AI architecture built for agents

    June 17, 2026
    Most Popular
    • The Integrated Search Brief That Aligns SEO, PPC & Content In The AI Search Era
    • Microsoft Ads expands LinkedIn targeting with job seniority filters
    • HPE Discover: Neri outlines an AI architecture built for agents
    • Schema, LLMs & The Low Bar For ‘Evidence’ In GEO
    • Google Ads shifts Demand Gen billing to CPM for some Discover campaigns
    • TikTok Shows 3x More AI Slop Than YouTube, Report Finds
    • Why prevention is cheaper than recovery
    • Bing Rolls Out AI Citation Share In Webmaster Tools
    © 2026 WifiPortal.tech. Designed by WifiPortal.tech.
    • Home
    • About Us
    • Contact Us
    • Privacy Policy
    • Terms and Conditions
    • Disclaimer

    Type above and press Enter to search. Press Esc to cancel.