Recent research has unveiled serious security vulnerabilities in four popular extensions for Microsoft Visual Studio Code (VS Code), collectively installed over 125 million times. These vulnerabilities could potentially allow attackers to steal local files and execute code remotely.
Identified Vulnerabilities
The affected extensions include Live Server, Code Runner, Markdown Preview Enhanced, and Microsoft Live Preview. According to OX Security researchers Moshe Siman Tov Bustan and Nir Zadok, a single malicious extension or a vulnerability in one extension can enable lateral movement within organizations, compromising their security.
Details of the vulnerabilities are as follows:
- CVE-2025-65717 (CVSS score: 9.1) – This vulnerability in Live Server allows attackers to exfiltrate local files by tricking a developer into visiting a malicious website while the extension is active. The embedded JavaScript can crawl and extract files from the local development HTTP server running at localhost:5500, sending them to an external domain. (Remains unpatched)
- CVE-2025-65716 (CVSS score: 8.8) – Found in Markdown Preview Enhanced, this flaw permits attackers to execute arbitrary JavaScript code by uploading a specially crafted markdown (.md) file, enabling local port enumeration and file exfiltration. (Remains unpatched)
- CVE-2025-65715 (CVSS score: 7.8) – This vulnerability in Code Runner allows attackers to execute arbitrary code by persuading a user to modify the “settings.json” file through phishing or social engineering tactics. (Remains unpatched)
- A vulnerability in Microsoft Live Preview enables attackers to access sensitive files on a developer’s machine by tricking the victim into visiting a malicious site while the extension is active. This allows specially crafted JavaScript requests targeting localhost to enumerate and exfiltrate sensitive files. (No CVE, fixed silently by Microsoft in version 0.4.16 released in September 2025)
Security Recommendations
To mitigate risks associated with these vulnerabilities, users are advised to avoid applying untrusted configurations, disable or uninstall unnecessary extensions, and strengthen their local network security by using a firewall to control inbound and outbound connections. Regularly updating extensions and disabling localhost-based services when not in use are also recommended practices.
OX Security emphasizes that poorly designed or overly permissive extensions can execute code, modify files, and allow unauthorized access to machines, posing a significant threat to organizational security. Keeping vulnerable extensions installed can lead to severe security breaches, as it may only take a single click or a downloaded repository to compromise an entire system.
This article was produced by NeonPulse.today using human and AI-assisted editorial processes, based on publicly available information. Content may be edited for clarity and style.
Original source: thehackernews.com








