Severe VS Code Extension CVEs Expose Developers to RCE and File Exfiltration
ID: c713f1cc-93ec-5789-9147-a36b8cfd7ca3
STIX ID: report--c713f1cc-93ec-5789-9147-a36b8cfd7ca3
Feed Name: SOCRadar Blog
This report details a coordinated disclosure of serious vulnerabilities in several widely used Visual Studio Code extensions—CVE-2025-65715 (Code Runner, RCE), CVE-2025-65716 (Markdown Preview Enhanced, arbitrary JS execution), CVE-2025-65717 (Live Server, local file exfiltration)—plus an XSS issue in Microsoft Live Preview. It explains affected versions (researchers say many versions are likely impacted), realistic exploitation paths tied to normal developer behaviors (workspace settings, previewing files, local servers), the presence of PoC demonstrations but no broad KEV listing, and immediate defensive actions: disable/uninstall vulnerable extensions, enforce extension allowlisting, treat workspace settings as untrusted, reduce localhost exposure, and update Microsoft Live Preview to 0.4.16+.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
