HomeSecuritySerious vulnerabilities in popular VSCode extensions

Serious vulnerabilities in popular VSCode extensions

A new cybersecurity warning highlights critical vulnerabilities affecting some of the most popular Visual Studio Code (VSCode) extensions. The extensions have collectively exceeded 128 million downloads, making the issue of particular concern to the global developer community.

VSCode

According to researchers, the security vulnerabilities could be exploited by attackers to steal local files, execute remote code , and potentially take over systems.

Which extensions are affected?

The issues are found in well-known VSCode plugins such as:

  • Code Runner (CVE-2025-65715)
  • Markdown Preview Enhanced (CVE-2025-65716 and CVE-2025-65717)
  • Microsoft Live Preview (no official CVE ID)

See also: What 5 million applications revealed about JavaScript secrets

These vulnerabilities were identified by application security company Ox Security, which has been trying to notify extension maintainers since June 2025. However, as the researchers themselves report, there has been no response from maintainers, raising concerns about user exposure.

Why VSCode extensions are a target

Visual Studio Code extensions are a key part of Microsoft's IDE . They add features like language support, debugging tools, themes, and automation that make developers' daily work easier.

The problem is that extensions run with significant access rights in the local environment: they can interact with files, terminals, and even network resources. So a vulnerability in a popular extension can become a “gateway” for an attacker.

Remote code execution and data theft

Ox Security warns that the use of vulnerable extensions can lead to lateral movement within corporate networks, data theft , and complete takeover of development systems.

A prime example is the critical vulnerability CVE-2025-65717, which affects Live Server, an extension with over 72 million downloads. Through it, an attacker can steal local files simply by directing the target to a malicious website.

Serious vulnerabilities in popular VSCode extensions

Similarly, the CVE-2025-65715 vulnerability in Code Runner (37 million downloads) allows remote code execution by modifying the extension's configuration file. An attacker could trick the user into pasting malicious settings into settings.json, triggering dangerous commands.

See also: Keenadu: New backdoor detected in Android firmware

Markdown files as an attack vehicle

With a severity rating of 8.8, CVE-2025-65716 affects the Markdown Preview Enhanced extension, which has been downloaded more than 8.5 million times. The vulnerability allows JavaScript to be executed from specially crafted Markdown files, turning a seemingly harmless document into an attack tool.

Additionally, a one-click XSS vulnerability was found in Microsoft Live Preview versions prior to 0.4.16, allowing access to sensitive files on the computer. The extension has surpassed 11 million downloads.

Cursor and Windsurf IDEs are also affected

Interestingly, the issues aren't limited to VSCode. The same extensions are also used in alternative AI-powered IDEs like Cursor and Windsurf , which rely on compatibility with the VSCode ecosystem

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

See also: Password Managers vulnerable to breach by malicious server

This means that the risk extends to an even larger number of developers, especially those who leverage artificial intelligence tools for code development.

Serious vulnerabilities in popular VSCode extensions

What should developers do now?

Experts recommend immediate protective measures, such as:

  • Avoid running localhost servers unnecessarily
  • Do not open untrusted HTML or Markdown files
  • Beware of settings snippets pasted into settings.json
  • Removing unnecessary extensions
  • Install only from trusted publishers
  • Monitor for suspicious changes to IDE settings

In an era where IDEs are a central point of development and a target of attacks, extension security is not just a detail, but a critical factor in protecting data and infrastructure.

Source: www.bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr/politiki-syntaxis/
Member of the SecNews Editorial Team. Covers software vulnerabilities, data breaches, cyberattacks and technology developments. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS