Skip to content

Workspace Trust Security Feature Bypass Vulnerability

High
kycutler published GHSA-9mw4-h26x-gfxw Jul 14, 2026

Package

No package listed

Affected versions

< 1.128.1

Patched versions

1.128.1

Description

A security feature bypass vulnerability exists in VS Code 1.128.0 and earlier versions where, under certain conditions, specially crafted notebook content could bypass security restrictions in Restricted Mode.

Patches

The fix is available starting with VS Code 1.128.1. The fix mitigates this attack by improving how untrusted notebook content is handled.

Workarounds

Do not open notebooks from untrusted sources on versions of VS Code <=1.128.0.

References

Severity

High

CVE ID

CVE-2026-57101

Weaknesses

No CWEs