logo

Flaws in Popular Software Development App Extensions Allow Data Exfiltration

ID: 41436384-40db-5cc7-b74c-ebe3df860dd8

STIX ID: report--41436384-40db-5cc7-b74c-ebe3df860dd8

Feed Name: Infosecurity Magazine (News)

Threat Score
75/100

Date Published: 2026-02-19

Date Updated: 2026-04-22

...
...

Researchers at OX Security disclosed four vulnerabilities impacting Visual Studio Code and two of its "vibe coding" forks (Cursor, Windsurf); three of the flaws received CVE IDs (CVE-2025-65717, CVE-2025-65716, CVE-2025-65715) and enable file exfiltration and remote code execution via popular extensions (Live Server, Markdown Preview Enhanced, Code Runner) with millions of downloads, while a fourth Live Preview issue was silently fixed by Microsoft—OX also provided mitigation steps for users and recommendations for extension maintainers and marketplaces.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.