A new cybersecurity warning highlights critical vulnerabilities affecting some of the most popular Visual Studio Code (VSCode) extensions. The extensions have collectively exceeded 128 million downloads, making the issue of particular concern to the global developer community.

According to researchers, the security vulnerabilities could be exploited by attackers to steal local files, execute remote code , and potentially take over systems.
Which extensions are affected?
The issues are found in well-known VSCode plugins such as:
- Code Runner (CVE-2025-65715)
- Markdown Preview Enhanced (CVE-2025-65716 and CVE-2025-65717)
- Microsoft Live Preview (no official CVE ID)
See also: What 5 million applications revealed about JavaScript secrets
These vulnerabilities were identified by application security company Ox Security, which has been trying to notify extension maintainers since June 2025. However, as the researchers themselves report, there has been no response from maintainers, raising concerns about user exposure.
Why VSCode extensions are a target
Visual Studio Code extensions are a key part of Microsoft's IDE . They add features like language support, debugging tools, themes, and automation that make developers' daily work easier.
The problem is that extensions run with significant access rights in the local environment: they can interact with files, terminals, and even network resources. So a vulnerability in a popular extension can become a “gateway” for an attacker.
Remote code execution and data theft
Ox Security warns that the use of vulnerable extensions can lead to lateral movement within corporate networks, data theft , and complete takeover of development systems.
A prime example is the critical vulnerability CVE-2025-65717, which affects Live Server, an extension with over 72 million downloads. Through it, an attacker can steal local files simply by directing the target to a malicious website.

Similarly, the CVE-2025-65715 vulnerability in Code Runner (37 million downloads) allows remote code execution by modifying the extension's configuration file. An attacker could trick the user into pasting malicious settings into settings.json, triggering dangerous commands.
See also: Keenadu: New backdoor detected in Android firmware
Markdown files as an attack vehicle
With a severity rating of 8.8, CVE-2025-65716 affects the Markdown Preview Enhanced extension, which has been downloaded more than 8.5 million times. The vulnerability allows JavaScript to be executed from specially crafted Markdown files, turning a seemingly harmless document into an attack tool.
Additionally, a one-click XSS vulnerability was found in Microsoft Live Preview versions prior to 0.4.16, allowing access to sensitive files on the computer. The extension has surpassed 11 million downloads.
Cursor and Windsurf IDEs are also affected
Interestingly, the issues aren't limited to VSCode. The same extensions are also used in alternative AI-powered IDEs like Cursor and Windsurf , which rely on compatibility with the VSCode ecosystem
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
See also: Password Managers vulnerable to breach by malicious server
This means that the risk extends to an even larger number of developers, especially those who leverage artificial intelligence tools for code development.

What should developers do now?
Experts recommend immediate protective measures, such as:
- Avoid running localhost servers unnecessarily
- Do not open untrusted HTML or Markdown files
- Beware of settings snippets pasted into settings.json
- Removing unnecessary extensions
- Install only from trusted publishers
- Monitor for suspicious changes to IDE settings
In an era where IDEs are a central point of development and a target of attacks, extension security is not just a detail, but a critical factor in protecting data and infrastructure.
Source: www.bleepingcomputer.com
