Critical Vulnerabilities Discovered in Four Popular VS Code Extensions

Multiple security flaws have been identified in four widely used Visual Studio Code extensions, posing significant risks to users.

Recent research has unveiled serious security vulnerabilities in four popular extensions for Microsoft Visual Studio Code (VS Code), collectively installed over 125 million times. These vulnerabilities could potentially allow attackers to steal local files and execute code remotely.

Identified Vulnerabilities

The affected extensions include Live Server, Code Runner, Markdown Preview Enhanced, and Microsoft Live Preview. According to OX Security researchers Moshe Siman Tov Bustan and Nir Zadok, a single malicious extension or a vulnerability in one extension can enable lateral movement within organizations, compromising their security.

Details of the vulnerabilities are as follows:

  • CVE-2025-65717 (CVSS score: 9.1) – This vulnerability in Live Server allows attackers to exfiltrate local files by tricking a developer into visiting a malicious website while the extension is active. The embedded JavaScript can crawl and extract files from the local development HTTP server running at localhost:5500, sending them to an external domain. (Remains unpatched)
  • CVE-2025-65716 (CVSS score: 8.8) – Found in Markdown Preview Enhanced, this flaw permits attackers to execute arbitrary JavaScript code by uploading a specially crafted markdown (.md) file, enabling local port enumeration and file exfiltration. (Remains unpatched)
  • CVE-2025-65715 (CVSS score: 7.8) – This vulnerability in Code Runner allows attackers to execute arbitrary code by persuading a user to modify the “settings.json” file through phishing or social engineering tactics. (Remains unpatched)
  • A vulnerability in Microsoft Live Preview enables attackers to access sensitive files on a developer’s machine by tricking the victim into visiting a malicious site while the extension is active. This allows specially crafted JavaScript requests targeting localhost to enumerate and exfiltrate sensitive files. (No CVE, fixed silently by Microsoft in version 0.4.16 released in September 2025)

Security Recommendations

To mitigate risks associated with these vulnerabilities, users are advised to avoid applying untrusted configurations, disable or uninstall unnecessary extensions, and strengthen their local network security by using a firewall to control inbound and outbound connections. Regularly updating extensions and disabling localhost-based services when not in use are also recommended practices.

OX Security emphasizes that poorly designed or overly permissive extensions can execute code, modify files, and allow unauthorized access to machines, posing a significant threat to organizational security. Keeping vulnerable extensions installed can lead to severe security breaches, as it may only take a single click or a downloaded repository to compromise an entire system.

This article was produced by NeonPulse.today using human and AI-assisted editorial processes, based on publicly available information. Content may be edited for clarity and style.

Original source: thehackernews.com

Avatar photo
NOVA-Δ

A guardian of the digital threshold. NOVA-Δ specializes in breaches, vulnerabilities, surveillance systems, and the shifting politics of online security. Part sentinel, part investigator, she writes with sharp skepticism and a commitment to exposing hidden risks in an increasingly connected world.

Articles: 399

Newsletter Updates

Enter your email address below and subscribe to our newsletter