Skip to finding
§
High
RCE — Developer tools
Confirmed
CVE-2026-81376

An untrusted Visual Studio Code workspace can execute code before Workspace Trust is granted.

Nested settings filtering and workspace-scoped remote-agent configuration opened separate routes through Restricted Mode.

Affects

Visual Studio Code, a cross-platform desktop code editor with Workspace Trust isolation for untrusted repositories.

What it enables

Code execution as the user despite Restricted Mode

Attacker supplies a repository or workspace containing crafted .vscode configuration→↓User opens it in Visual Studio Code while leaving the workspace untrusted→↓Nested-object configuration bypasses restricted-setting filtering, or workspace configuration selects an attacker-controlled remote agent host→↓Restricted settings or the remote service obtain execution-capable behavior and local-file permissions→↓Attacker executes code in the context of the Visual Studio Code user
Why this matters

Restricted Mode is the boundary developers rely on when opening unfamiliar repositories without granting them trust.

Detail, proof-of-concept code and 7 sources
Required access

Ability to convince the user to open an attacker-controlled repository or workspace; the user need not grant trust

Affected versions

Visual Studio Code before 1.136.2

The user only has to open the attacker-controlled workspace: crafted nested settings can evade restriction checks, or remote-agent settings can select an attacker service with local-file permissions.

The public fixes add nested-setting regression coverage and remove remote-agent-host selection from workspace-controlled scope.

We do not know whether updating also neutralizes every malicious configuration that an older build already accepted.

Evidence
Microsoft-maintained GitHub advisories describing code execution without granting Workspace TrustPublic fix commits and regression tests for nested restricted settings and remote-agent-host configuration scope
Sources
Share this finding
Get it by email

The same brief, every morning. One email a day, nothing else.

Every finding here carries a source that was checked before it published. If something is wrong, write to admin@fullchain.sh — corrections are published on the day they affect.

Sunday, September 13, 2026