Cybersecuritynews Critical Vulnerabilities in VS Code Extensions Expose Developers to Attacks
Article Content
Browse articles
Multiple vulnerabilities affecting popular Visual Studio Code (VS Code) extensions, including the Live Preview extension, have been discovered, exposing developers to risks such as local file exfiltration and remote code execution. The flaws, identified by researchers from OX Security, impact extensions with over 128 million downloads. Key vulnerabilities include CVE-2025-65715, CVE-2025-65716, and CVE-2025-65717, all published on February 16, 2026.
Ask AI about this cluster
Answers cite the sources they use
Updated 182d ago How this analysis works
Timeline
2026-02-16
CVE-2025-65715 published
2026-02-16
CVE-2025-65716 published
2026-02-16
CVE-2025-65717 published
2026-02-18
Microsoft Live Preview vulnerability reported
More articles in this cluster (18)
Following this threat?
Track OX Security and CVE-2025-65715 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical Stored XSS Vulnerabilities Found in SiYuan Versions Before 3.7.4 Two critical vulnerabilities, CVE-2026-73050 and CVE-2026-73052, have been identified in SiYuan versions prior to 3.7.4. CVE-2026-73050 allows attackers to exploit stored cross-site scripting (XSS) via unescaped color fields in select options, executing arbitrary JavaScript in victim browsers. CVE-2026-73052 enables…