Close Menu
    Facebook X (Twitter) Instagram
    Wifi PortalWifi Portal
    • Blogging
    • SEO & Digital Marketing
    • WiFi / Internet & Networking
    • Cybersecurity
    • Tech Tools & Mobile / Apps
    • Privacy & Online Earning
    Facebook X (Twitter) Instagram
    Wifi PortalWifi Portal
    Home»Cybersecurity»Flaws in popular VSCode extensions expose developers to attacks
    Cybersecurity

    Flaws in popular VSCode extensions expose developers to attacks

    adminBy adminFebruary 18, 2026No Comments3 Mins Read
    Facebook Twitter LinkedIn Telegram Pinterest Tumblr Reddit WhatsApp Email
    Flaws in popular VSCode extensions expose developers to attacks
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Flaws in popular VSCode extensions expose developers to attacks

    Vulnerabilities with high to critical severity ratings affecting popular Visual Studio Code (VSCode) extensions collectively downloaded more than 128 million times could be exploited to steal local files and execute code remotely.

    The security issues impact Live Server (CVE-2025-65715), Code Runner (CVE-2025-65716), Markdown Preview Enhanced (CVE-2025-65717), and Microsoft Live Preview (no identifier assigned).

    Researchers at application security company Ox Security discovered the flaws and tried to disclose them since June 2025. However, the researchers say that no maintainer responded.

    Wiz

    Remote code execution in IDE

    VSCode extensions are add-ons that expand the functionality of Microsoft’s integrated development environment (IDE). They can add language support, debugging tools, themes, and other functionality or customization options.

    They run with significant access to the local development environment, including files, terminals, and network resources.

    Ox Security published reports for each of the discovered flaws and warned that keeping the vulnerable extensions could expose the corporate environment to lateral movement, data exfiltration, and system takeover.

    An attacker exploiting the CVE-2025-65717 critical vulnerability in the Live Server extension (over 72 million downloads on VSCode) can steal local files by directing the target to a malicious webpage.

    The CVE-2025-65715 vulnerability in the Code Runner VSCode extension, with 37 million downloads, allows remote code execution by changing the extension’s configuration file. This could be achieved through tricking the target into pasting or applying a maliciously configuration snippet in the global settings.json file.

    Rated with a high-severity score of 8.8, CVE-2025-65716 affects the Markdown Preview Enhanced (8.5 million downloads) and can be leveraged to execute JavaScript via maliciously crafted Markdown file.

    Ox Security researchers discovered a one-click XSS vulnerability in versions of Microsoft Live Preview before 0.4.16. It can be exploited to access sensitive files on a developer’s machine. The extension has more than 11 million downloads on VSCode.

    The flaws in the extensions also apply to Cursor and Windsurf, which are AI-powered VSCode-compatible alternative IDEs.

    Ox Security’s report highlights that the risks associated with a threat actor leveraging the issues include pivoting on the network and stealing sensitive details like API keys and configuration files.

    Developers are advised to avoid running localhost servers unless necessary, opening untrusted HTML while they’re running, and applying untrusted configurations or pasting snippets into settings.json.

    Also, it is advisable to remove unnecessary extensions and only install those from reputable publishers, while monitoring for unexpected setting changes.


    tines

    Modern IT infrastructure moves faster than manual workflows can handle.

    In this new Tines guide, learn how your team can reduce hidden manual delays, improve reliability through automated response, and build and scale intelligent workflows on top of tools you already use.

    attacks Developers Expose Extensions Flaws popular VSCode
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Telegram Email
    Previous ArticleNew Report Helps Journalists Dig Deeper Into Police Surveillance Technology
    Next Article NotebookLM Slide Decks just got way more flexible
    admin
    • Website

    Related Posts

    Liongard upgrades LiongardIQ with AI access, live asset data, and deeper discovery

    April 18, 2026

    Critical flaw in Protobuf library enables JavaScript code execution

    April 18, 2026

    Tycoon 2FA Loses Phishing Kit Crown Amid Surge in Attacks

    April 18, 2026
    Add A Comment
    Leave A Reply Cancel Reply

    Search Blog
    About
    About

    At WifiPortal.tech, we share simple, easy-to-follow guides on cybersecurity, online privacy, and digital opportunities. Our goal is to help everyday users browse safely, protect personal data, and explore smart ways to earn online. Whether you’re new to the digital world or looking to strengthen your online knowledge, our content is here to keep you informed and secure.

    Trending Blogs

    Liongard upgrades LiongardIQ with AI access, live asset data, and deeper discovery

    April 18, 2026

    Critical flaw in Protobuf library enables JavaScript code execution

    April 18, 2026

    Dive Into The Stanford Report Data

    April 18, 2026

    Claude Cowork took one repetitive task for me, and I’m very impressed

    April 18, 2026
    Categories
    • Blogging (65)
    • Cybersecurity (1,385)
    • Privacy & Online Earning (171)
    • SEO & Digital Marketing (847)
    • Tech Tools & Mobile / Apps (1,653)
    • WiFi / Internet & Networking (232)

    Subscribe to Updates

    Stay updated with the latest tips on cybersecurity, online privacy, and digital opportunities straight to your inbox.

    WifiPortal.tech is a blogging platform focused on cybersecurity, online privacy, and digital opportunities. We share easy-to-follow guides, tips, and resources to help you stay safe online and explore new ways of working in the digital world.

    Our Picks

    Liongard upgrades LiongardIQ with AI access, live asset data, and deeper discovery

    April 18, 2026

    Critical flaw in Protobuf library enables JavaScript code execution

    April 18, 2026

    Dive Into The Stanford Report Data

    April 18, 2026
    Most Popular
    • Liongard upgrades LiongardIQ with AI access, live asset data, and deeper discovery
    • Critical flaw in Protobuf library enables JavaScript code execution
    • Dive Into The Stanford Report Data
    • Claude Cowork took one repetitive task for me, and I’m very impressed
    • Tycoon 2FA Loses Phishing Kit Crown Amid Surge in Attacks
    • ConnectBot v1.10.4 by Kenny Root
    • AI traffic converts better than non-AI visits for U.S. retailers: Report
    • Horizon Lock on the Galaxy S26 Ultra is amazing, but Motorola did it first. Here’s how they compare
    © 2026 WifiPortal.tech. Designed by WifiPortal.tech.
    • Home
    • About Us
    • Contact Us
    • Privacy Policy
    • Terms and Conditions
    • Disclaimer

    Type above and press Enter to search. Press Esc to cancel.