Skip to content

Python extension for Visual Studio Code Remote Code Execution Vulnerability #25253

@karthiknadig

Description

@karthiknadig

There is a security vulnerability in the untrusted workspaces flow with specially crafted workspaces.

Patches

The fix is available starting with 2025.8.1 fix is: 5e64d0e

Workarounds

Check for python executables checked-into SCM before opening untrusted workspaces.

References

Metadata

Metadata

Assignees

Labels

bugIssue identified by VS Code Team member as probable bug

Type

No type

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions