Tools AI Risk Radar ai-incident-0078
Incident record
VS Code agent network filters bypassed by alternate URL and address representations
- Severity
- High
- Status
- Patched
- Type
- Agent Hijack
- Target
- Visual Studio Code before 1.136.2
- Actor
- researcher
- CVE
- CVE-2026-81378, CVE-2026-81357
What happened
Microsoft disclosed two bypasses in optional agent network filtering. Backslashes or mixed separators let the integrated browser interpret a URL differently from the policy checker; equivalent IPv4-mapped IPv6 addresses bypassed IPv4 entries in deny-only policies. Both require particular filter configurations and are fixed in 1.136.2. Each advisory assigns CVSS 3.1 8.2; neither reports confirmed exploitation.
Until updated, Microsoft advises disabling integrated-browser chat tools for the URL-parsing flaw and using a nonempty explicit allow-list for the address-representation flaw. These are two related vulnerabilities grouped into one radar record.
Sources
- Microsoft: URL-parsing advisorygithub.com/microsoft/vscode/security/advisories/GHSA-4gv7-q2…
- Microsoft: IPv4/IPv6 advisorygithub.com/microsoft/vscode/security/advisories/GHSA-4xcg-6m…
One record from the AI Risk Radar, maintained by the Security Desk. Data: CSV · JSON ·RSS · CC BY 4.0 with attribution to YFarmX.Tracker updated · 18 September 2026