Critical Vulnerabilities Discovered in Four Popular VS Code Extensions
- Securityish
- Threats & Incidents
Quick Summary
The Securityish Brief
Researchers have identified critical security vulnerabilities in four widely used Microsoft Visual Studio Code (VS Code) extensions: Live Server, Code Runner, Markdown Preview Enhanced, and Microsoft Live Preview. Collectively, these extensions have been installed over 125 million times. The vulnerabilities allow attackers to steal local files and execute code remotely, significantly compromising the security of developers and organizations.
Details of the vulnerabilities include CVE-2025-65717, which has a CVSS score of 9.1 and allows attackers to exfiltrate local files by tricking developers into visiting malicious websites. Another vulnerability, CVE-2025-65716, scores 8.8 and enables arbitrary JavaScript code execution via crafted markdown files. Additionally, CVE-2025-65715 in Code Runner permits code execution through manipulated settings files.
Microsoft Live Preview also has a vulnerability that allows access to sensitive files on a developer’s machine, although it has been fixed silently in version 0.4.16 released in September 2025. The unpatched vulnerabilities in Live Server, Markdown Preview Enhanced, and Code Runner remain a significant threat.
Understanding the Risks
The presence of these vulnerabilities highlights the risks associated with poorly designed or malicious extensions. OX Security researchers emphasize that even a single compromised extension can lead to lateral movement within an organization, potentially compromising sensitive data. Keeping vulnerable extensions installed poses an immediate threat to security posture.
To mitigate these risks, developers and organizations should be vigilant about the extensions they use. Regularly updating extensions, disabling unnecessary ones, and avoiding untrusted configurations are essential practices. Additionally, hardening local networks and turning off localhost-based services when not in use can help protect against potential exploits.
As the use of VS Code extensions continues to grow, so does the need for awareness regarding their security implications. Developers must remain informed about vulnerabilities and take proactive measures to safeguard their development environments.
Key Takeaways
- Regularly update all installed VS Code extensions to ensure you have the latest security patches.
- Disable or uninstall any non-essential extensions to reduce your attack surface.
- Harden your local network by using a firewall to restrict inbound and outbound connections.
- Turn off localhost-based services when they are not in use to prevent unauthorized access.
- Be cautious of untrusted configurations and avoid using extensions from unknown sources.
Key Terms & Concepts
- CVE: CVE stands for Common Vulnerabilities and Exposures, a list of publicly disclosed cybersecurity vulnerabilities.
- CVSS: CVSS, or Common Vulnerability Scoring System, is a standard for assessing the severity of security vulnerabilities.
Your 5-Minute Securityish Brief
A weekly digest of cybersecurity news, phishing alerts, privacy tips, and emerging threats, simplified so anyone can understand what matters and why.
Securityish
Securityish explains cybersecurity, scams, data breaches, and privacy risks in simple language so you know what’s happening and how to protect yourself.
Navigation
Your 5-Minute Cybersecurity Brief
A weekly digest of cybersecurity news, phishing alerts, privacy tips, and emerging threats, simplified so anyone can understand what matters and why.