CVE-2026-70334
Incomplete list of disallowed inputs in Visual Studio Code allows an unauthorized attacker to bypass a security feature locally.
Scoring
- Severity
- HIGH
- CVSS base score
- 7.8
- CVSS vector
- CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
- CWE
- CWE-184
- Published
- 2026-09-08
- Last modified
- 2026-09-09
Affected products
- Microsoft Visual Studio Code
Weakness type
Related vulnerabilities
- CVE-2026-79696 — Remote Code Execution in Google ADK for Python via Incomplete Standard Library Denylist
- CVE-2026-82536 — Roo-Code 3.54.0 Auto-Approve Bypass via Shell Command Pipe Operator
- CVE-2026-69624 — Active Directory Certificate Services (AD CS) Tampering Vulnerability
- CVE-2026-33197 — BDS Module Bypass Secure Boot Advisory
- CVE-2026-85787 — An incomplete list of disallowed inputs in the SQL validation component of Amazon awslabs postgres-mcp-server
- CVE-2026-77124 — Nexus Repository 3 - Script Execution Disable Setting Not Enforced
- CVE-2026-84370 — SVGO: removeScripts allows executable links through namespace and control-character bypasses
- CVE-2026-84218 — Org.jolokia/jolokia-core: incomplete jndi denylist in jolokia jsr-160 proxy (bypass of cve-2018-1000130 fix)