Tools AI Risk Radar ai-incident-0079
Incident record
Untrusted VS Code repositories could configure a remote agent host with local-file access
- Severity
- High
- Status
- Patched
- Type
- Agent Hijack
- Target
- Visual Studio Code before 1.136.2
- Actor
- researcher
- CVE
- CVE-2026-78462
What happened
VS Code read remote agent host addresses and local-file permission grants from workspace configuration. Opening a crafted repository could connect the editor to an attacker-controlled host and permit local data access or code execution, even without trusting the workspace. Opening the repository required user interaction. Version 1.136.2 restricts these settings to global configuration.
Microsoft assigns CVSS 3.1 8.8. The advisory describes the vulnerability and fix without reporting confirmed exploitation.
Sources
- Microsoft: remote agent host advisory and fixgithub.com/microsoft/vscode/security/advisories/GHSA-2cmq-rv…
One record from the AI Risk Radar, maintained by the Security Desk. Data: CSV · JSON ·RSS · CC BY 4.0 with attribution to YFarmX.Tracker updated · 18 September 2026