CVE-2026-54981
Inclusion of functionality from untrusted control sphere in Visual Studio Code - Python extension allows an unauthorized attacker to bypass a security feature locally.
Scoring
- Severity
- HIGH
- CVSS base score
- 7.8
- CVSS vector
- CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
- EPSS probability
- 0.39%
- CWE
- CWE-829, CWE-693
- Published
- 2026-08-11
- Last modified
- 2026-09-16
Affected products
- Microsoft Python extension for Visual Studio Code
Weakness type
Related vulnerabilities
- CVE-2026-0770 — Langflow exec_globals Inclusion of Functionality from Untrusted Control Sphere Remote Code Execution Vulnerability
- CVE-2025-32463 — Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled director
- CVE-2025-34074 — Lucee Admin Interface Authenticated Remote Code Execution via Scheduled Job File Write
- CVE-2024-38476 — Apache HTTP Server may use exploitable/malicious backend application output to run local handlers via internal redirect
- CVE-2026-27941 — OpenLIT Vulnerable to Remote Code Execution and Secret Exposure via Misuse of `pull_request_target` in GitHub Actions Workflows
- CVE-2026-1699 — In the Eclipse Theia Website repository, the GitHub Actions workflow .github/workflows/preview.yml used pull_request_tar
- CVE-2025-34060 — Monero Forum Remote Code Execution via Arbitrary File Read and Cookie Forgery
- CVE-2025-66022 — FACTION Unauthenticated Custom Extension Upload leads to RCE